logoalt Hacker News

h43ztoday at 9:40 AM3 repliesview on HN

Reminder to be cautious about leaking public keys.

Once you leak your public key it could be used to check if another server recognizes that leaked public key.


Replies

alentredtoday at 11:54 AM

Did I miss something? Aren't public key are supposed to be public?

To be clear, that's an honest question, not sarcasm of anything. I only assume I don't know about some corner case with SSH or something? Because we have those on our websites, they are supposed to be used to verify signatures, etc. How is publishing them bad?

show 1 reply
benj111today at 10:18 AM

Surely you shouldn't be leaking your username. I could use it to see if another server recognised 'h43z'....

show 1 reply
Zambytetoday at 9:52 AM

What?

show 1 reply