4 ms·
The .ssh/authorized_keys contains public keys. Technically, these can be completely public, as it is infeasible to compute the corresponding private key to get
by ProblemFactory 14y ago
The .ssh/authorized_keys contains public keys. Technically, these can be completely public, as it is infeasible to compute the corresponding private key to get access. However, keeping it secret may be useful, in case a hacker compromises another computer that you own with private keys on it.
If the authorized_keys file is published, they immediately know which private keys are useful for remote logins.
If the authorized_keys file contains source-machine names and usernames in the comment, it gives the hackers a list of your other machines to attempt compromising to obtain the private keys.
If the authorized_keys file uses from="address" restrictions, publishing it gives the hackers a list of allowed source networks for remote logins. If they try to log in with the correct private key from the wrong network, they are denied access (and may assume the key is invalid).
In summary, it's technically not a security risk, but there is no reason to publish it and make life easier for hackers if they do happen to stumble on one of your private keys.