|
|
|
|
|
by foobiekr
1299 days ago
|
|
I think you’d be surprised how many large companies have such poor control of their signing servers that anyone in the company with a valid login and engineering group membership can generate signatures for arbitrary artifacts. |
|
Trust me, I'm not at all surprised, but my point stands: it's either a compromise of the company or the key.