Re: For CAs: What makes a Good Incident Response?

2019-08-22 Thread Dean C via dev-security-policy
On Wednesday, August 21, 2019 at 3:43:21 PM UTC-4, Ryan Sleevi wrote: > (Apologies if this triple or quadruple posts. There appears to be some > hiccups somewhere along the line between my mail server and the m.d.s.p. > mail server and the Google Groups reflector) > > I've recently shared some cho

For CAs: What makes a Good Incident Response?

2019-08-21 Thread Ryan Sleevi via dev-security-policy
I've recently shared some choice words with several CAs over their Incident Reporting process, highlighting to them how their approach is seriously undermining trust in their CA and the operations. While https://wiki.mozilla.org/CA/Responding_To_An_Incident provides Guidance on the minimum expecta

For CAs: What Makes a Good Incident Response

2019-08-21 Thread Ryan Sleevi via dev-security-policy
(Apologies if this triple or quadruple posts. There appears to be some hiccups somewhere along the line between my mail server and the m.d.s.p. mail server) I've recently shared some choice words with several CAs over their Incident Reporting process, highlighting to them how their approach is ser

For CAs: What makes a Good Incident Response?

2019-08-21 Thread Ryan Sleevi via dev-security-policy
(Apologies if this double posts; (my || the) e-mail gateway seems to be having some trouble so I'm trying this through the Google Groups interface) I've recently shared some choice words with several CAs over their Incident Reporting process, highlighting to them how their approach is seriously

For CAs: What makes a Good Incident Response?

2019-08-21 Thread Ryan Sleevi via dev-security-policy
(Apologies if this triple or quadruple posts. There appears to be some hiccups somewhere along the line between my mail server and the m.d.s.p. mail server and the Google Groups reflector) I've recently shared some choice words with several CAs over their Incident Reporting process, highlighting t