11 points | by GaryBluto 13 hours ago ago
3 comments
> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.
Unencrypted signing key. They just don’t care anymore.
Why wasnt that key in an HSM?
Discussion on source: https://news.ycombinator.com/item?id=49253250
> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.
Unencrypted signing key. They just don’t care anymore.
Why wasnt that key in an HSM?
Discussion on source: https://news.ycombinator.com/item?id=49253250