Mozilla revokes Firefox signing key after unencrypted copy lands in GitHubtheregister.com 12 pointsGaryBluto1 month ago3 commentsSaveHideCopy link On HNComments−winstonwinston1moafter an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.Unencrypted signing key. They just don’t care anymore.−ChrisArchitect1moDiscussion on source: https://news.ycombinator.com/item?id=49253250−shim__1moWhy wasnt that key in an HSM?
Comments
Unencrypted signing key. They just don’t care anymore.
Discussion on source: https://news.ycombinator.com/item?id=49253250
Why wasnt that key in an HSM?