logoalt Hacker News

smashedyesterday at 4:01 PM1 replyview on HN

An official government source is teaching users to ignore security warnings about expired certificates.

Mistakes happen, some automation failed and the certs did not renew on time, whatever. Does not inspire confidence but we all know it happens.

But then to just instruct users to click through the warning is very poor judgement on top of poor execution.


Replies

dmitrygryesterday at 4:05 PM

This was the predictable outcome of shortening certificate length validity to appoint where they are now.

show 2 replies