Skip to content

Comment on Ask HN: SSL Certs need to be revoked, right?

Comments

Yes. If you run something sensitive, you should also consider:

- Invalidating any open sessions (i.e. cookies), since those could have been stolen.

- Force password changes for all users (since those could have been intercepted in memory)

- Change internal passwords.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.