zlacker

[parent] [thread] 1 comments
1. Genbox+(OP)[view] [source] 2022-03-05 14:40:14
What gruez said is correct. Hardware token have been mandated for EV certificates for a long time by providers to prevent leaks.

I'll also add that Amazon Key Management Service, Azure Key Vault, and Google Key Management Service store several hundred million private keys combined with no leaks so far (they are non-exportable and access is audited)

It is very rare that we see malware signed by a publisher's certificate, which is why it is in the news every time it happens.

replies(1): >>hulitu+563
2. hulitu+563[view] [source] 2022-03-06 18:39:02
>>Genbox+(OP)
No leaks does not imply security.
[go to top]