In the hearing NY DA said they get over half of the phones today but it doesn’t happen fast enough (suggesting hours and days are necessary) and that the other police departments just can’t do what they can. (e.g. they want to make this ability more readily available)
Hmmm. I think you might be flipping between build servers and signing servers as is convenient for your argument, but the reality is that a compromise of either is sufficient, no?
-
-
It depends; if the prod signing infra is online then build servers and signing infra is synonymous. If separated and designed to mitigate insider threats then its different.
-
Sneaking in a defect into large source control happens, and if you can, and you are patient, that defect will ultimately get signed. It’s very unlikely this is quicker than using zero days but it is possible to do.
- 30 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.