Hacker News new | ask | show | jobs
by counterpointer 4733 days ago
The signing keys are the weakest link in the security infrastructure and are essentially the keys to the kingdom. We have seen this happen repeatedly, I think it's time for all companies to build a lot of safeguards around the use of their private signing keys, like making employees input it manually everytime, or even split it across multiple employees. For Opera at least, I don't think they do releases that frequently.