|
|
|
|
|
by caf
4031 days ago
|
|
If GitHub did not publish public keys, then I could then reasonably expect that I was safe for the life of that key. I don't think so, because of the way GitHub's SSH access works - you don't need to know the account associated with a given key to try and authenticate with that key, so trying all 32k "Debian keys" of each size and seeing which ones let you in is quite feasible. |
|