Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you use this to id people for authentication?

As in if someone pings your server and you get a key that matches their GitHub is it really that person's key or could they be doing it without having the corresponding private key?



Anyone can download the public key and impersonate that person in a scheme like this.


Unless you require them to authenticate using that key (which would obviously require them to have the private key on hand).


What you are describing is the current status quo




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: