Earlier quoted context omitted.
> I assume the AWS resources have been rekeyed by now It doesn't look like the SSL cert on instagram.com has changed recently, and the pentester specifically claims to have obtained its private key.
a private key. It's not uncommon to have multiple simultaneously-valid certificates for the same domain. I'd argue that it's actually sort of irresponsible and therefore surprising for a site at the scale of Instagram not to, for backup purposes.
Re: Instagram's Million Dollar Bug
#561but using that private key can still grant him access to someone's traffic to their machines. isn't revocation necessary to imply security in that domain ever again?