Having a public register of public keys makes it easy to give people access to your organization, CI/CD etc.
Having a public register of public keys makes it easy to give people access to your organization, CI/CD etc.
There are cryptographic protocols where public keys are kept private. For example TLS with client certificates (the client's certificate gets sent encrypted to the server). Ditto SSHv2 (the client need not reveal all its public keys, and it does get to authenticate the server before revealing its identity and public keys).
Hmm... I was under the impression that up until TLS 1.3 the client cert was sent in the clear during session negotiation...
That's a very strong overstatement. With this argument, you could argue that data leaks involving names, emails, etc are fine, because emails and names are meant to be public.
Not a big deal, but I forgot about that leak, so "expose" made me read further and be reminded that clearly I am not a blackhat, or any color hat for that matter.