I have PTSD from trying to explain that public keys are meant to be shared despite the word "key".
That's okay, my PTSD is from people sending their private key when I asked for their public key.
It does highlight a critical difference between "security" and "privacy", though.
It lifts your public keys as much as "git clone git@github.com" does.
They are not stored long-term anywhere, FWIW.
There's no mention of all your public keys being stored on connection, right? It's just comparing public keys it gets sent against what's already public on GitHub
This is like saying there should be a warning for every single website that it lifts your IP address and user agent.
what does "lifted" mean in the context of your public keys (that you published at GitHub if it can tie them to anything?)?
In fairness, many people don't expect github to publish those keys (even if they are public keys)