3 ms·
It would not expose SSH keys, but the location of SSH keys.
by actionfromafar 1mo ago
It would not expose SSH keys, but the location of SSH keys.
- wongarsu 1mo agoAnd what is even the concern about that? I don't mind software knowing that my ssh key is in ~/.ssh/id_ed25519. Maybe if you see a 500 byte ~/.ssh/id_rsa that's an issue, but then the real issue is the tiny key Thinking about threat scenarios of directory structure access, I'd be much more concerned about exposing that I have ~/documents/work/mergers/2027/[secret]_WarnerBros-Fox.docx But only being able to see the file name would still be a huge improvement over being able to open the document and exfiltrate it