Hacker News new | ask | show | jobs
by stouset 1181 days ago
They don’t need it. Millions of users are going to blindly trust the “new” GitHub public SSH key they see the next time they connect without checking to see if it matches the published signature.