3 ms·
I wonder why the private keys of these signing-certificates don't live exclusisvely in HSMs. At least if they do, then the range of suspects should be pretty n
by cimnine 5y ago
I wonder why the private keys of these signing-certificates don't live exclusisvely in HSMs.
At least if they do, then the range of suspects should be pretty narrow.
- deleted 5y ago[deleted]
- Denvercoder9 5y agoThey probably do, I expect that the keys aren't leaked but that a way to convince the real system into signing fake data was found, or one of the systems feeding data was compromised.