Updated GPG Key for Signing Firefox and Thunderbird Releases
blog.mozilla.org
Updated GPG Key for Signing Firefox and Thunderbird Releases
1–10 of 19 posts
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#2Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#3If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#4If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
The signing key for Firefox stored on a single hardware yubikey available to a single person?
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#5If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#6If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#7If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#8Earlier quoted context omitted.
People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
Storing the secret on a hardware token will most certainly help with not committing into source control.
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#9If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
The signing key for Firefox stored on a single hardware yubikey available to a single person?
Re: Updated GPG Key for Signing Firefox and Thunderbird Releases
#10If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
...as opposed to? What's your criteria for "non-security-theater"?