3 comments

[ 0.22 ms ] story [ 2.0 ms ] thread
Why wasnt that key in an HSM?
> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.

Unencrypted signing key. They just don’t care anymore.