Back to News
Advertisement
Advertisement

⚑ Community Insights

Discussion Sentiment

50% Positive

Analyzed from 83 words in the discussion.

Trending Topics

#hardware#key#signing#yubikey#something#single#subkey#committed#implies#developers

Discussion (4 Comments)Read Original on HackerNews

noman-landβ€’about 1 hour ago
If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
Joel_Mckayβ€’6 minutes ago
People don't need an extra supply-chain failure mode to consider, and CVE-2024-45770 proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
anon7000β€’about 1 hour ago
The signing key for Firefox stored on a single hardware yubikey available to a single person?
computerfriendβ€’about 1 hour ago
Multiple hardware devices can have the same key.