Hacker News new | ask | show | jobs
by eganist 1300 days ago
> anyone in the company with a valid login and engineering group membership can generate signatures for arbitrary artifacts.

Trust me, I'm not at all surprised, but my point stands: it's either a compromise of the company or the key.