Reply to post: Re: Why ?

Compromised SSH keys used to access Spotify, UK Govt GitHub repos

John Robson Silver badge

Re: Why ?

I took all of my existing keys out of use, and reissued the lot, because I couldn't remmeber exactly when each had been generated (or necessarily on which machine).

But to expect that level of action from everyone with a github account?

In the same way I expect browsers to flag up bad certs I'd expect SSH banners to warn about these compromised keys - or simply ignore them (with error in the server log at least, preferably in the banner)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon