Hacker News new | ask | show | jobs
by brians 3594 days ago
So the evil32 people kept the private keys. That's exciting.
1 comments

Not necessarily, they might have just generated revokation certs which are separate (so that they can be used in case your private key is lost). Keeping a revokation cert would be a responsible thing to do, just in case something like this happens.
They had an old backup that contained the private keys. See this comment https://news.ycombinator.com/item?id=12298230