5 ms·
> out of an abundance of caution, we replaced our RSA SSH host [...] > GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository What
by dskloet 3y ago
> out of an abundance of caution, we replaced our RSA SSH host [...]
> GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository
What the... That's not "an abundance of caution". That's the only possible course of action.
- awill 3y agoYou're absolutely right. It's absurd to frame it this way. Do they expect people to think "Wow, Github leaked a key, but even without knowing if anyone snagged it, they're still replacing it. Wow, they go above and beyond." It's so ridiculous.
- Xenoamorphous 3y agoNot playing devil’s advocate but guess they at least have some confidence that no one checked out/pulled the repo while the key was there? After all it’s them hosting and serving the requests for that (and every other) repo.
- diggan 3y agoThere is a literal stream of all public data on GitHub. I don't think they can 100% know if it was accessed or not.
- colonwqbang 3y ago"We have no reason to believe" => We don't actually know
- execveat 3y agoCharitable explanation is that they rotated they key without waiting for an analysis.
- sebzim4500 3y agoTo be fair, there are somehow people in this post who seem to be arguing that GH should not rotate the key.
- irjustin 3y ago> That's the only possible course of action. Only _reasonable_ course of action. Possible is to do nothing =)
- ars 3y agoThey mean they are not sure if anyone actually downloaded the private key. That's the "caution" part.