This seems like they are taking credit for an existing ssh feature that requires little-to-no server-side support?
I think by "security key" they are talking about working with yubikey instead of the regular public/private ssh keys. I don't know much about yubikey, but it sounds like it is a usb drive for storing you ssh private keys with some software for managing them. They must be promoting yubikey.
Not sure if GitHub have pushed their server side code upstream, I think they were using libssh.
Yeah I don't get it either. Git and ssh client need support. I wouldn't think the server would even know that your private key is backed by a hardware security key.
Good! I've been waiting for this feature for a while. I think truly was the last bit of functionality I wanted to give my Yubikey. Fantastic.