16 points | by csmantle an hour ago ago
3 comments
If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
The signing key for Firefox stored on a single hardware yubikey available to a single person?
Multiple hardware devices can have the same key.
If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
The signing key for Firefox stored on a single hardware yubikey available to a single person?
Multiple hardware devices can have the same key.