4 ms·
This is a step in the right direction. Although if i’m not mistaken the case for somebody stealing your .ssh directory with keys and contributing to GitHub over
by sdfhbdf 4y ago
This is a step in the right direction. Although if i’m not mistaken the case for somebody stealing your .ssh directory with keys and contributing to GitHub over SSH still stands.
I guess it’d be hard to require everybody to password protect their ssh keys.
- wiredfool 4y agoI suspect that if your main branch was protected, an attacker would be restricted to branches that require active access to automatically get into a distribution.
- psanford 4y agoThe vast majority of attacks these days are not via compromised desktop environments. They are from phishing, password reuse + third party password compromises, and weak passwords. Its these most common attacks that Github is addressing with this change.