Reply to post: Re: I'd like to know

Equifax IT staff had to rerun hackers' database queries to work out what was nicked – audit

stiine Silver badge

Re: I'd like to know

Assuming that their production systems had current, non-expired certificates, then the copies of the old certificates on the monitoring system wouldn't have allowed the monitoring system to actually decrypt the data, and as was pointed out above, their system was configured to fail-open, instead of fail-closed.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon