188
Sysadmins slam Apple’s SSL/TLS cert lifespan cuts
(www.theregister.com)
This is a most excellent place for technology news and articles.
This seems counter-intuitive to the goal of "improving internet security". Automation is a double-edged sword. Convenient, sure, but also an attack vector, one where malicious activity is less likely to be noticed, because actual people aren't involved in tbe process, anymore.
We've got ample evidence of this kinda thing with passwords: increasing complexity requirements and lifetime requirements improves security, only up to a point. Push it too far, and it actually ends up DECREASING security, because it encourages bad practices to get around the increased burden of implementation.
https://feddit.org/post/3295548