Comment on Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
eleijeep@piefed.social 23 hours ago
The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response.
Yeah, I bet I know why.
noodlejetski@piefed.social 19 hours ago
but they prompted it not to make mistakes, how could that happen?!