Hacker News

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

12 points by GaryBluto ago | 3 comments

winstonwinston |next [-]

> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.

Unencrypted signing key. They just don’t care anymore.

shim__ |next |previous [-]

Why wasnt that key in an HSM?

ChrisArchitect |previous [-]