Private keys committed to Github repositories
1–10 of 31 posts
Re: Private keys committed to Github repositories
#2No, this is people committing their private keys to a Github repository. Github is not at fault.
edit: submitter has since updated the title, was: "Github giving away your private key"
Re: Private keys committed to Github repositories
#3Can someone just write a script that crawls this page for updates, then sends the users an email telling them what they did?
Re: Private keys committed to Github repositories
#4No, this is people committing their private keys to a Github repository. Github is not at fault. edit: submitter has since updated the title, was: "Github giving away your private key"
Seriously.
It looks like people have added their private keys to (public!!!) repos, and voila, a search allows others to find that.
Re: Private keys committed to Github repositories
#5.ssh should probably be on a default .gitignore list, along with .DS_Store
Re: Private keys committed to Github repositories
#6Github is serving up private keys for those that added them to a git repository. I was wondering how they would be giving away my private key ... without me giving it to them.
Re: Private keys committed to Github repositories
#7I hope people take the high road here and dont make an example out of github members. People make mistakes. You dont need to delete their repo to show them. A friendly email will do.
Also Github, provide an option to protect those who are less security savy.
Re: Private keys committed to Github repositories
#8Definitely a "you did what?" situation but probably still newsworthy since the new search tool makes the user's error easier to exploit and the publicity about the tool will make it more likely that someone will exploit it.
Re: Private keys committed to Github repositories
#9Finally a github search that works!!!!
Re: Private keys committed to Github repositories
#10No, this is people committing their private keys to a Github repository. Github is not at fault. edit: submitter has since updated the title, was: "Github giving away your private key"
I would say it's shared responsability.
Yes commiting private data is stupid, and the other hand, just testing the new sesarch by trying to search for rsa key could Have Avoided this.
Anyway, as usual the main problem exist between the chair and the keyboard.