more discussion https://news.ycombinator.com/item?id=37955264
post
Hmm, wonder if there was some reason they didnt just extract the original certificates from the VPS if it was actually the hosting provider, I mean even with mitigation it should be sitting in a temp folder somewhere, surely they could? Issuing new ones seems like a surefire way to alert the operators, unless they already used Let's Encrypt of course.
replies:
all 4 comments