this post was submitted on 29 Jun 2024
19 points (95.2% liked)
Pulse of Truth
464 readers
77 users here now
Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).
This community is automagically fed by an instance of Dittybopper.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It's called Let's Encrypt. Holy shit, get with the fucking programme, Microsoft.
They're their own certificate authority and they let their intermediaries expire too. It's partially automated they just don't monitor it. Similar to when your certbot reports it couldn't renew because of whatever reason, maybe dns validation failure or whatever. It usually tells you like 30-60 days before expiry and there's lots of time.
Microsoft has both the tools and knowledge and still doesn't get them all. Every year. One time it blocked mfa and login services. Sometimes it's just teams. It's like they just figured instead of staff monitoring they figure user feedback like their insider program is just cheaper.