Looking at the two best guesses: a reasonable assumption, if the Certifi bundle was in fact the target of this attack, is that some consumer of that bundle is that true target of this attack.
(Incidentally: I'm not familiar with what the Certifi bundle is, and some quick DDGing didn't turn it up.)
As a recent convo I'd had here on HN turned up, key management is a crucial element of PKI, which includes not only SSH and PGP, but the CA-based measures: SSL and TLS.
Your web link is only as secure as the least-paranoid developer's MX registrations in your entire development toolchain.
Comments
Looking at the two best guesses: a reasonable assumption, if the Certifi bundle was in fact the target of this attack, is that some consumer of that bundle is that true target of this attack.
(Incidentally: I'm not familiar with what the Certifi bundle is, and some quick DDGing didn't turn it up.)
As a recent convo I'd had here on HN turned up, key management is a crucial element of PKI, which includes not only SSH and PGP, but the CA-based measures: SSL and TLS.
Your web link is only as secure as the least-paranoid developer's MX registrations in your entire development toolchain.