Damus
Silberengel · 4d
Ditto’s bug was arbitrary JavaScript in the app WebView (XSS), not RCE, from which they could drive the app. Including the session keys, but no stealing of the key.
:H::e::n::k::y:!! · 3d
If in theory it was tampered with you'd just have to revoke it in your signer. I don't think anyone exploited it in the wild.