4 ms·
You know, if I was 17 and bored, I’d look up all of the keys for all of the people from national security agencies that have contributed to open source projects
by numair 5y ago
You know, if I was 17 and bored, I’d look up all of the keys for all of the people from national security agencies that have contributed to open source projects on GitHub and see if anything noteworthy turns up anywhere.
- semiquaver 5y agoWhat you describe isn’t possible since commits are not associated publicly with SSH keys in any way.
- gpm 5y agoThey are if you sign them...
- larusso 5y agoyou mean gpg sign? By the way the gpg public keys are also available via a URL. https://github.com/Larusso.gpg https://github.com/Larusso.gpg Edit If course you mean the new signing feature which will come to git and GitHub in the future. Sorry
- gpm 5y agoYou're entirely right, just a brain fart on my part that those are different keys. Not sure why you're downvoted.
- lou1306 5y agoSomewhat related: a friend of mine crawled across a ton of publicly available PDFs from several security agencies and found a lot of interesting metadata about their setup (stuff like OS version, word processor of choice, even the author's names in some cases). https://therecord.media/security-agencies-leak-sensitive-data-by-failing-to-sanitize-pdf-files/ https://therecord.media/security-agencies-leak-sensitive-dat...