3 ms·
Github is exposing public SSH keys
- jrgifford 14y agoDuplicate. http://news.ycombinator.com/item?id=5023665 http://news.ycombinator.com/item?id=5023665 Also, it doesn't make a difference, since they are public keys, like public GPG keys. They also aren't the only ones that do this - LaunchPad.net (where Ubuntu development takes place) also does it. https://code.launchpad.net/~jamesgifford/+sshkeys https://code.launchpad.net/~jamesgifford/+sshkeys
- jlarocco 14y agoIsn't being public the point of public keys?
- oh_sigh 14y agoA problem arises if users start to use github as a defacto trusted source for public keys. Githubs security standards are very high, but they have a large potential attack surface due to all of the functionality they support.
- oh_sigh 14y agoSo what? Is somebody going to factorize my public key? This is only an issue if 1) Users are relying on github as a trusted source of public keys, and 2) malicious users can modify the public keys.
- geofft 14y agoIt doesn't even have key names. Boring. (But useful -- I can provision accounts on servers I run with "oh I set up .ssh/authorized_keys with your Github keys"; thanks!)
- RegEx 14y agoLaunchpad accounts have ssh keys as part of public user profiles. Should be ok :) Ex: https://launchpad.net/~brad-figg https://launchpad.net/~brad-figg
- kylemaxwell 14y agoIn other news: HN is revealing the user names of its users! Film at 11!
- mattvanhorn 14y agoCan someone help me understand why it is a problem if my public key is, uh, public?
- antihero 14y agoWorst case scenario is that someone lets me access their server. Unless RSA is busted, right?