Comment on A sneaky demonstration of the dangers of curl bash

<- View Parent
xylogx@lemmy.world ⁨20⁩ ⁨hours⁩ ago

What you said is the key infra needs to get compromise. I do not need to own the PKI that issued the certs, I just need the private key of the signer. And again, this is something that happens. A lot. A software publisher gets owned, then their account is used to distribute malware.

source
Sort:hotnewtop