Re: Trustico code injection

2018-03-02 Thread randomsyseng--- via dev-security-policy
> Trustico have assured us that the private key > could not have been compromised. Did they elaborate on how they came to that "could not have been" conclusion? ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mo

Re: Private key corresponding to public key in trusted Cisco certificate embedded in executable

2017-06-20 Thread randomsyseng--- via dev-security-policy
> Moral of the story, if you have to ask if it's a disclosure, you are better > safe than sorry and keeping the info under close wraps until you confirm it. I think it's better it was disclosed than had it not been disclosed at all. While I agree to an extent that there could have been more opt