News: 1679664867

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

GitHub publishes RSA SSH host keys by mistake, issues update

(2023/03/24)


GitHub has updated its SSH keys after accidentally publishing the private part to the world. Whoops.

A [1]post on Github's security blog reveals that the company has changed its RSA SSH host keys. This is going to cause connection errors, and some frightening warning messages, for a lot of developers, but it's all right: it's not scary cracker activity, just plain old human error.

[2]Microsoft subsidiary GitHub is the largest source code shack in the world, with an estimated 100 million active [3]users . So this is going to inconvenience a lot of people. It's not the end of the world: if you normally push and pull to GitHub via SSH – which most people do – then you will have to delete your local GitHub SSH key, and fetch new ones.

[4]

As the blog post describes, the first symptom is an alarming warning message: @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!

For almost everyone, this warning is spurious. It's not that you're being attacked – although that is always a remote ( [5]ha ha, only serious ) possibility – it's that GitHub revoked its old keys and published new ones. Hanlon's Razor applies, as it most often does:

Never attribute to malice that which can be adequately explained by stupidity.

(The word stupidity is often replaced with incompetence , but then, one does tend to lead to the other.)

This time, the reason was – as usual – plain old human error. Someone published GitHub's private RSA keys in a repository on GitHub itself. If you're unclear how SSH encryption works, about public versus private keys, or the different cryptographic algorithms SSH uses, there are many good [6]explanations out there.

[7]

[8]

In brief and as most Reg readers know, it is fine and good to reveal, publish and share public keys, but your private keys must be kept secret. If they get out – for instance, if someone accidentally publishes them on a high-profile website – then anyone who has them can pretend to be you. That is bad.

[9]GitHub Copilot learns new tricks, adopts this year's model

[10]GitHub rolls out mandatory 2FA for loads of devs next week

[11]GitHub claims source code search engine is a game changer

[12]Microsoft, GitHub, OpenAI urge judge to bin Copilot code rip-off case

SSH supports alternative cryptographic [13]algorithms to RSA for its keys, and GitHub [14]also has ECDSA and Ed25519 keys as well. Those were not published, so they haven't changed.

GitHub isn't saying who published the keys or where, which is perfectly fine, but we suspect that information might trickle out later on. At any rate, at 0500 UTC today it changed the RSA for a new one, so you should follow the instructions in the blog post, delete the old key, and add the new ones, as soon as possible. ®

Bootnote

Hanlon's Razor itself is a corollary of [15]Finagle's Law : Whatever can go wrong, will go wrong. And as an ironic but rather good example of that, it could well be that Robert J. Hanlon was actually slightly [16]misquoting Robert A. Heinlein, and so it really ought to be Heinlein's Razor.

Get our [17]Tech Resources



[1] https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/

[2] https://www.theregister.com/2018/06/04/microsoft_buys_github/

[3] https://github.blog/2023-01-25-100-million-developers-and-counting/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZB3XNKJlvxxnkMnzVD6jgAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://en.wiktionary.org/wiki/ha_ha_only_serious

[6] https://www.digitalocean.com/community/tutorials/understanding-the-ssh-encryption-and-connection-process

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZB3XNKJlvxxnkMnzVD6jgAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZB3XNKJlvxxnkMnzVD6jgAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/03/22/github_copilot_learns_new_tricks/

[10] https://www.theregister.com/2023/03/09/github_2fa_requirement/

[11] https://www.theregister.com/2023/02/07/github_code_search/

[12] https://www.theregister.com/2023/01/31/microsoft_github_openai_copilot/

[13] https://goteleport.com/blog/comparing-ssh-keys/

[14] https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/githubs-ssh-key-fingerprints

[15] http://www.catb.org/jargon/html/F/Finagles-Law.html

[16] https://quoteinvestigator.com/2016/12/30/not-malice/

[17] https://whitepapers.theregister.com/



Sex, Drugs, Money and ...

Eclectic Man

Prof Fred Piper of Royal Holloway College, University of London claimed that the three most popular ways of defeating encryption were 'sex, drugs and money'. I suppose we ought to add 'stupidity' to that list.

"Whoops!" indeed.

It is Friday, have a pint to drown your sorrows.

Re: Sex, Drugs, Money and ...

John H Woods

I would have thought "Violence" probably comes first on that list (Including the state telling you "Hand over your keys or else ...")

Re: Sex, Drugs, Money and ...

John Riddoch

Because there's an XKCD for everything: [1]https://xkcd.com/538/

[1] https://xkcd.com/538/

Re: Sex, Drugs, Money and ...

Steve Button

Oh yes, when a nerd's fantasy meets cold hard reality.

I've been a nerd long enough to have bumped into cold hard reality too many times, and have the scars to prove it.

A bit like the great philosopher Mike Tyson who said "Everyone has a plan, until they get punched in the mouth".

If you're unclear how SSH encryption works, about public versus private keys

Steve Button

It's pretty simple really., the "private" part is the part you are supposed to keep private. Like really private.

That image (which I assume is only on the RSS feed?) sums it up really nicely. Someone is very much tearing their hair out.

This is going to cause a small amount of disruption for millions of people, and probably a large amount of disruption for an unfortunate few who have inherited a system that they only half understand.

Oopsie.

Encrypted?

John H Woods

Were the private keys published encrypted or not? Or does it not make much difference?

Re: Encrypted?

Steve Button

Yes it makes a huge difference. If the key was encrypted they could have sorted this out with a bit more leisure, or perhaps not even worried about much depending on how good the encryption is.

Zippy´s Sausage Factory

Wait, GitHub did what?

Oh yes, Microsoft subsidiary. Business as usual, then.

I experience that...

chololennon

I experienced that 12 hours ago when I was pushing several commits (the first group Ok, the second one, a few minutes later, with the scary message)... and of course I panic because it wasn't my rsa key, but the one from GitHub. So I checked my keys, I checked my GitHub account... I ended up updating my keys and the ones from GitHub. My worry lasted until I read this article, thanks Liam.

Sufficiently advanced stupidity

Mike 16

is indistinguishable from malice

Scintillate, scintillate, globule vivific,
Fain how I pause at your nature specific,
Loftily poised in the ether capacious,
Highly resembling a gem carbonaceous.
Scintillate, scintillate, globule vivific,
Fain how I pause at your nature specific.