3 ms·
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
- ChrisArchitect 2mo agoDiscussion on source: https://news.ycombinator.com/item?id=49253250 https://news.ycombinator.com/item?id=49253250
- shim__ 2mo agoWhy wasnt that key in an HSM?
- winstonwinston 2mo ago> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. Unencrypted signing key. They just don’t care anymore.