$ ssh whoami.filippo.io @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: POSSIBLE DNS SPOOFING DETECTED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ The ED25519 host key for whoami.filippo.io has changed I guess I've tried this before
ssh whoami.filippo.io
11–20 of 90 posts
[deleted]
Re: ssh whoami.filippo.io
#12[flagged]
[deleted]
Re: ssh whoami.filippo.io
#13Re: ssh whoami.filippo.io
#14[flagged]
It lifts your public keys as much as "git clone git@github.com" does.
They are not stored long-term anywhere, FWIW.
Re: ssh whoami.filippo.io
#15[flagged]
There's no mention of all your public keys being stored on connection, right? It's just comparing public keys it gets sent against what's already public on GitHub
Re: ssh whoami.filippo.io
#16[flagged]
what does "lifted" mean in the context of your public keys (that you published at GitHub if it can tie them to anything?)?
Re: ssh whoami.filippo.io
#17[flagged]
This is like saying there should be a warning for every single website that it lifts your IP address and user agent.
Re: ssh whoami.filippo.io
#18Today I learned that GitHub keeps a publicly accessible list of all pubkeys linked to each user's account.
Re: ssh whoami.filippo.io
#19The idea of walking up to a lock and saying “here are all of my keys. Do any unlock you?” is kind of weird and backwards.
But I realize, thinking about it, I was doing that all the time at a previous job where I’d just mash my entire wallet against the keycard reader.
Bonus tangent: join me in playing “Payment Roulette” where you mash your wallet against payment terminals and let your credit and debit cards sort out which is going to pay.