Hacker News new | ask | show | jobs
by eightysixfour 488 days ago
It happened again after rolling it, so a dev’s machine is compromised, the prod infra is, or they’re straight serving the key somewhere.
1 comments

Exactly. If I had to bet I would guess their server is just straight up serving the file. I've seen that way too many times.