Hacker News new | ask | show | jobs
by pjc50 1631 days ago
"Secure" is kind of a relative term, it only exists with regard to a threat model and a likely spectrum of attacks. Simply having the key in plaintext on a developer PC connected to the regular internet is fairly low-security to start with; there are all sorts of opportunities for coincidental compromise that may have exposed it directly from his PC or his collaborator's PC.
1 comments

Agreed, all I'm saying is that he did not give any specific detail which demonstrated a specific vulnerability. so just feel like more info is needed.