Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But if I understand it right, it was Google that screwed up this one. I always thought that they were not taking their responsibility as an OS vendor seriously and they should have taken this horse in back of the barn and shot it years ago.


Given what we know so far, there's no indication that Google is associated with this at all.


If I was a betting man: some smaller fish in the Android ecosystem practiced exquisitely terrible key management outside an HSM, got burnt, and will have to slip KPMG or Deloitte an extra big kickback if they ever want to see a clean SOC 2 again.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: