At least I learned a lot from the github issues their hacker opened. Wonder if there are any surviving archives of those that the repo owners did not delete in shame.


I (the repo owner) reposted them via links to archive.org after github deleted them, actually: https://github.com/matrix-org/matrix.org/issues/367#issuecom.... See https://matrix.org/blog/2019/05/08/post-mortem-and-remediati... for the full details of what happened, fwiw.

As much as I love ridiculing matrix, I must admit that’s a beautiful move. Thank you, and apologies for laughing at the parent post.

Were the GPG signing keys the hacker found for signing official Debian packages for Matrix-related software?

They were for signing the Debian and Ubuntu packages of the matrix.org Debian repos. But Debian also has its own packages for matrix-synapse (with the latest version usually available in experimental) -- so you could just use those instead.

