Skip to content

Comment on Matrix.org Security Incidentparent

Comments

it was not, read again

But it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.

It seems the issue was developers using SSH agent forwarding which was abused to access the production environment.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.