Hacker News new | ask | show | jobs
by ShadowRegent 1018 days ago
> Am I right to assume that because the attacker had the signing key all of the extra authentication mechanisms that would have been enabled on accounts were bypassed by the attacker...?

That's my understanding.