5 ms·
I don't know whether this is clever or not. But it ID'd me from my Github account public keys.
by Normille 4y ago
I don't know whether this is clever or not. But it ID'd me from my Github account public keys.
- woodruffw 4y agoI think it's pretty clever, and demonstrates something very powerful about GitHub's position as de facto global code repository: you can get a strong cryptographic identity for (almost) anyone on the service, which you can then sign/encrypt to, verify for, etc. age (another tool of Filippo's) leverages this to make encrypting to any GitHub user easy[1]. [1]: https://github.com/FiloSottile/age#encrypting-to-a-github-user https://github.com/FiloSottile/age#encrypting-to-a-github-us...
- tcard 4y ago> you can get a strong cryptographic identity for (almost) anyone on the service, which you can then sign/encrypt to, verify for, etc. I made https://sshign.tcardenas.me/ https://sshign.tcardenas.me/ to take advantage of this. For example: [1] In the end, it isn't that useful. I only routinely sign digitally to deal with the (Spanish) government, and they provide their own certificates and software to do that. [1] https://sshign.tcardenas.me/?signer=github.com%2Ftcard&message=%3E+you+can+get+a+strong+cryptographic+identity+for+%28almost%29+anyone+on+the+service%2C+which+you+can+then+sign%2Fencrypt+to%2C+verify+for%2C+etc.%0A%0AI+made+https%3A%2F%2Fsshign.tcardenas.me%2F+to+take+advantage+of+this.&signature=ssh-rsa%7CHqnDdkqG3s4_SMu9FUkdHH3jrxDupM4GPpwsUcvXJOcqJjA62ceh5SuiPFBnMzmo0GDU6BlOdbIcnifQhF9V5BRUeqng5DosNy_xJW36va9VQwDW9NwxkaCQVJengKpc8aDpx_unxr0S7Nr69louo5ab0EjOvb1ailFa8RYEuEHU5nWIJJ0IhcqncQUXqqzxTeoAkoGr3IcJkeWkI3VfjJDwRt1bfQ5wLcj3WeD_BH3kqbhZtkeQ1mHRONqt76MBktR8EZiBhwdhkrMfejJpe64zI5mCuhQnC7Ufrw3QNTUEdvBfxjSIauiIeqBJK8OCiGStMFPwepDdebZQVCjfSg%3D%3D https://sshign.tcardenas.me/?signer=github.com%2Ftcard&messa...
- xwolfi 4y agoIn Hong Kong and France where I pay taxes we seem to only use passwords. Sadly nobody has hacked my tax account and paid them for me :D
- alexeldeib 4y agoSorry, this web UI encourages me to upload private keys? Immediate nope for serious usage. Nice for testing, like jwt.io, though. The signature verification is handy.
- frutiger 4y agoAs a side note public keys are available on GitHub, e.g. https://github.com/FiloSottile.keys https://github.com/FiloSottile.keys.