logoalt Hacker News

alentredtoday at 11:54 AM1 replyview on HN

Did I miss something? Aren't public key are supposed to be public?

To be clear, that's an honest question, not sarcasm of anything. I only assume I don't know about some corner case with SSH or something? Because we have those on our websites, they are supposed to be used to verify signatures, etc. How is publishing them bad?


Replies

h43ztoday at 12:30 PM

It's just something everyone should be aware of.

It's up to you to decide if it's okay that you send a server provider (in this case late.sh) a bunch of your public keys which he could for example use to probe other servers to see if you have access to them.

Everyone has different opsec.

show 1 reply