If the private key is public, it does nothing by definition and it may as well not exist!
Just use plain text, HTTP, or whatever and stop fooling yourself.
It’s like calling an open field a “secure facility”.
The name is not the thing, the map is not the territory.
Private keys are only private if they’re not public.
Get it? Get it?
https://news.ycombinator.com/newsguidelines.html
Edit: it looks like we've had to warn you about this multiple times before:
https://news.ycombinator.com/item?id=32039759 (July 2022)
https://news.ycombinator.com/item?id=27225044 (May 2021)
https://news.ycombinator.com/item?id=22938445 (April 2020)
https://news.ycombinator.com/item?id=21808005 (Dec 2019)
We have to eventually ban accounts that keep breaking the rules like this. I don't want to ban you, so if you'd please review them and stick to them from now on, we'd appreciate it.
Nobody is surprised that Apple is able to revoke this key, by the way.
Unfortunately, nobody else seems to either, which is why my comment is getting downvoted.
"Why is this a problem?" say people when the publishing of a private key is inherently the wrong thing to do, and will always lead to a bad consequence.
It doesn't matter who's key it is, how it was generated, how it was obtained, etc...
The purpose of private keys is to be kept secret. A published private key by definition is worthless. That will have a consequence. Either it'll be make-believe fairytale security, or someone else getting into your product, or what happened here: the third party who's keys were stolen changed the locks.
Meanwhile I'm at -4 and clocking down because people struggle to understand how keys and locks work, never mind cryptography.
> A published private key by definition is worthless.
If I publish the AACS _private_ key, is it now worthless?
Public-private key pairs only work if the private key is secret. If it’s not secret it doesn’t work.
This is a simple fact of how cryptography works. Or passwords, keys, or any secret like an API key, etc…
If you publish such things on GitHub, they instantly become “not what you’ve labelled it as”.
So you admit it's not completely worthless at that point only for specific use cases.
So we've established that a "private key" that is no longer private may still have uses to some people, it is not wholly "worthless."
Do you want to revise your earlier statement about the private key in the repo in question? Is it "worthless"? Is it a security problem? Do you know what that key is being used for?
From what I gather, the private key was private until it was leaked to / stolen by the team who published it for this use case.
I don't have enough context to say, because I have to admit that once published, the keypair corresponding to the private key is likely to be revoked/discarded.
That's precisely it! Publishing a private key -- anyone's -- invalidates the security of the private-public key pair, making it worthless as security.
There's going to be some consequence to this, such as the third party "changing the locks" and locking out you, or your users.
Similarly, it might allow hackers to intercept the comms, break into your code, or whatever.
The essential, fundamental point I'm trying to get across here is that it never ever makes sense to publish a private key, and then rely on it for any purpose.
I guess it would have been more difficult for Apple to find the key/device ID used in this scheme had these not been available on the first few pages linked by a lot of articles claiming iMessage is broken.
Had this not been publicly posted, someone would've been forced to at least open a log file.