logoalt Hacker News

noman-landtoday at 4:32 AM2 repliesview on HN

If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.


Replies

anon7000today at 4:48 AM

The signing key for Firefox stored on a single hardware yubikey available to a single person?

show 2 replies
Joel_Mckaytoday at 5:38 AM

People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3

show 3 replies