3 ms·
Because they may be used to learn the identity of an otherwise pseudoanonymous github account if one uses the same keys with another account that is tied to his
by Djrhfbfnsks 5y ago
Because they may be used to learn the identity of an otherwise pseudoanonymous github account if one uses the same keys with another account that is tied to his real identity.
- pmontra 5y agoOne key per service. I've got a directory full of them and a long .ssh/config
- OJFord 5y agoIf the account is intended to be anonymous, it should have its own keypair not shared with the real identity (or other independently anonymous account). I say this regardless of whether public keys are being.. publicised. User database could be leaked, say, or public keys visible to employees/logged. OpenSSH literally refers to them as 'identities' - if you're trying to be anonymous/anon w.r.t. another it goes without saying that you need to not use the same identity!