logoalt Hacker News

zahlmantoday at 9:11 AM1 replyview on HN

The new code changes from not existing, to existing.

Indeed, the key doesn't change. The new capability comes from the new code.

It would not be a re-evaluation of risk, because this is a new project. The evaluation of risk is supposed to come at the moment when the new capability is implemented, and consciously tied to an existing key type, which was previously advertised as non-secret.


Replies

weird-eye-issuetoday at 9:58 AM

They're obviously talking about on the client's end, not Google