Hacker News new | ask | show | jobs
by tyu2 2010 days ago
I'm not sure why you say it's interesting, signed binaries was always known to be a useless measure against APT level threats, getting signing keys is probably the easiest thing at that level. I remember Microsoft even publicly admitted they can't do shit against APT, so all of their "security" PR is essentially not real security, but that's been a thing with all megacorps for years now.
1 comments

Getting _a_ signing key is not equal to having access to SolarWind's signing key. It is interesting because it shows the extent of the breach.