N
Hacker Next
new
past
show
ask
show
jobs
submit
login
▲
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
(
theregister.com
)
12 points by
GaryBluto
17 hours ago
|
3 comments
add comment
Rendered at 21:28:38 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
winstonwinston 10 hours ago
[-]
> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.
Unencrypted signing key. They just don’t care anymore.
shim__ 13 hours ago
[-]
Why wasnt that key in an HSM?
ChrisArchitect 16 hours ago
[-]
Discussion on source:
https://news.ycombinator.com/item?id=49253250
Unencrypted signing key. They just don’t care anymore.