Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My point is that Chrome cannot always auto-update for all installations. From that standpoint I made the comment that an Internet based revocation code may not be sufficient, and disclosures/notifications will still need to be monitored by administrators.


orgs running such ridiculous setups can monitor revokes coming over the wire from google and selectively apply them themselves, if they just care about their busy-work jobs sitting reading security bulletins. I don't really care about the security of their made-up non-jobs and google shouldn't either. they can do what they like.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: