I've read that the Bit9 compromise involved the company's own encryption keys, which led to trouble for customers of Bit9's whitelisting services. Would you say this was likely a one-off incident, or should enterprises reconsider using application whitelisting technology? Is there any way to sniff out certificates that have been signed by malicious hackers?
