[deleted]
SSH Keys on GitHub
11–20 of 48 posts
Re: SSH Keys on GitHub
#12[deleted]
Re: SSH Keys on GitHub
#13Earlier quoted context omitted.
No. There are valid cases to upload SSH keys and other certificates or secrets. Preventing it would be annoying, and near impossible to be very effective. Just my $0.02.
I agree with you, but I can't imagine a use case for a secret that's not secret.
Re: SSH Keys on GitHub
#14Does Github have a responsibility to help people out with this kind of thing? What do you all think?
A better question would be: Could Github be successfully found liable for other users leaving their own keys in a public repository?
Re: SSH Keys on GitHub
#15Does Github have a responsibility to help people out with this kind of thing? What do you all think?
Re: SSH Keys on GitHub
#16[deleted]
Re: SSH Keys on GitHub
#17Earlier quoted context omitted.
No. There are valid cases to upload SSH keys and other certificates or secrets. Preventing it would be annoying, and near impossible to be very effective. Just my $0.02.
I agree with you, but I can't imagine a use case for a secret that's not secret.
Aside from things like that, I can't see it being a _common_ use case.
Re: SSH Keys on GitHub
#18If anything, I'd love to see somebody do a blog post instead about how they started scraping these results and/or the commit data firehose and messaging users who posted credentials
Re: SSH Keys on GitHub
#19Re: SSH Keys on GitHub
#20I feel like this gets posted every other month or so. I appreciate the awareness, but it doesn't seem like there's much new discussion or debate to have on the matter: folks continue to be a bit more careless with credentials than they ought to be / don't think about what pushing something to a public site means / etc, it would rock if GitHub was more proactive about messaging affected users, it sucks that it's hard…