Cooking up a half-baked bad idea involving ssh keys
rachelbythebay.com
rachelbythebay.com
Seriously, if you can design a honeypot that can convince programmers to log in with SSH, maybe you should just launch a Start-up.
Maybe most, but not all. It isn't an issue for everyone, but that doesn't mean it isn't an issue at all.
>Seriously, if you can design a honeypot that can convince programmers to log in with SSH, maybe you should just launch a Start-up.
There is a big difference between a site that sparks intellectual curiosity and a site that inspires someone to actually pay money.
That response is ridiculous. Should you have been operating under a pseudonym, this would be a way to tie that pseudonym to your real name.
I should be told that my public keys are made available by Github. Had I been, I wouldn't have had a public key on my account.
Edit: To be clear, this would only work if the same public key was used for both accounts.
Less nefariously: send them an email asking to regenerate the key.
> Thanks to our new servers, known bad keys from Debian and Ubuntu are now blacklisted. We estimate that about 1000 keys in our database were impacted by this. If you get authentication errors using keys that worked a day ago, please double-check that they are not on our blacklist. If they are, you should ensure your software is updated and generate new keys. We’ve got a guide to help you out with this.
https://github.com/blog/500-state-of-the-hub-rackspace-day-0
My entry would be to mass import everyones commit logs and use a machine learning alg to find gaps that correspond to popular broadcast television shows.
http://developer.github.com/v3/users/keys/
It seems mostly harmless, but I'm not sure I see the point of making this information available.
There's perhaps a meta-hack here on how to get to HN front page (albeit on a sunday) with a fairly silly "hack" idea.
That kind of data mining would probably be reasonably scary.
I'm not sure I understood the rest of it. The site rachelbythebay.com would have a public key for Bob from github, and try to get Bob to log in using his private key?
Seriously though, remember the whole "We found X... is this your Twitter account?" thing which appeared on the search results for some people back in 2011? Are they still that brazen about the internal shadow profiles?
While maybe this is "okay" for github to publish, they run a security-sensitive service and hidden API surprises like this could give some folks the impression that they don't take security seriously enough.
Turn the idea on its head: Find a way to use SSH based authentication for services and allow people to connect with their GitHub account, find a clever way to map AuthorizedKeysFile (via fuse or something) to https://github.com/%u.key (yeah, won't directly work that way of course).
At least in the multi-user environments I manage, PAM works well, and we maintain some custom PAM modules to do things like handle unpaid accounts with warnings then lockout.
It's a little complex but I don't know of any viable alternative -- setting up Kerberos on Slackware is a big pain last I checked. Maybe not relevant to single user machines, but that's not the context we're talking about here.
Disclaimer: I don't really know what I'm talking about.
If you collect a large amount of keys you can use algorithms to find common divisors anywhere in the set, and so make it easier to find easily factorable keys out of a big population.
i realise that just enumerating products would scale well, but is that how efficient factoring schemes work?
or am i misunderstanding?
Since ssh keys are user-submitted, we will have diversity and a chance of some subset of keys which weren't generated safely.
EDITED TO ADD: Bad CCC site, it doesn't link to the FactHacks slides: http://www.hyperelliptic.org/tanja/vortraege/facthacks-29C3....
and the above tactic starts at 11m in. huh; and it's just euclid - a non-unity gcd means two keys (products) have a shared prime (and you get one of the primes).
edit: also, "batch number field sieve" is the answer to my original question.
https://news.ycombinator.com/item?id=5495982
Basically, I saw that and went "wait, how does it get the key?", went digging, and found the keys endpoint. The rest evolved from there.
I don't think there are that many anonymous githubs accounts out there. Feel free to prove me wrong though.