Hacker News new | ask | show | jobs
by lxgr 460 days ago
By the analogy of SSH, this vulnerability is more of an exposed/incorrectly permissioned SSH agent Unix domain socket than a private key compromise.

Whether that's catastrophic or not will vary case by case and depends on what exactly you're securing with the key.