TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Github is exposing public SSH keys

10 pointsby appplemacover 12 years ago

8 comments

jrgiffordover 12 years ago
Duplicate. <a href="http://news.ycombinator.com/item?id=5023665" rel="nofollow">http://news.ycombinator.com/item?id=5023665</a><p>Also, it doesn't make a difference, since they are <i>public</i> keys, like public GPG keys. They also aren't the only ones that do this - LaunchPad.net (where Ubuntu development takes place) also does it.<p><a href="https://code.launchpad.net/~jamesgifford/+sshkeys" rel="nofollow">https://code.launchpad.net/~jamesgifford/+sshkeys</a>
oh_sighover 12 years ago
So what? Is somebody going to factorize my public key?<p>This is only an issue if 1) Users are relying on github as a trusted source of public keys, and 2) malicious users can modify the public keys.
geofftover 12 years ago
It doesn't even have key names. Boring. (But useful -- I can provision accounts on servers I run with "oh I set up .ssh/authorized_keys with your Github keys"; thanks!)
jlaroccoover 12 years ago
Isn't being public the point of <i>public</i> keys?
评论 #5024039 未加载
RegExover 12 years ago
Launchpad accounts have ssh keys as part of public user profiles. Should be ok :)<p>Ex: <a href="https://launchpad.net/~brad-figg" rel="nofollow">https://launchpad.net/~brad-figg</a>
mattvanhornover 12 years ago
Can someone help me understand why it is a problem if my public key is, uh, public?
antiheroover 12 years ago
Worst case scenario is that someone lets me access their server. Unless RSA is busted, right?
kylemaxwellover 12 years ago
In other news: HN is revealing the user names of its users! Film at 11!