Repository hosting service GitHub has announced that it will replace existing RSA SSH host keys with new ones as a precautionary measure after discovering that existing RSA SSH host keys were temporarily exposed in public repositories. .
“We acted immediately to contain the exposure and launched an investigation to understand the root cause and impact,” GitHub wrote in an article published on its site today. “This completes the key exchange. The user can see the change take effect in his next 30 minutes.”
The company said the change was made to protect users’ Git operations over SSH, particularly from potential threat actors trying to impersonate GitHub or intercept user activity. They say it was done to protect them. At the same time, he clarified that the move did not result from a compromise of his GitHub system or customer information.
Mike Hanley, GitHub’s CSO, wrote: “There is no reason to believe that the public key was misused and that this action was taken with due care.”
An SSH host key is a token used to authenticate a server and protect both the confidentiality and integrity of communications between a client and server.
More information on SSH keys can be found here. Microsoft has discovered an updated cryptomining malware tool targeting Linux systems.
“This key does not grant access to GitHub’s infrastructure or customer data,” said Hanley. “This change only affects his Git operations over his SSH using RSA. His web traffic to GitHub.com and HTTPS Git operations are unaffected.”
The company further added that only GitHub.com’s RSA SSH keys will be replaced and no changes will be required for ECDSA or Ed25519 users.
The GitHub RSA SSH host key replacement comes months after the company confirmed that a threat actor had stolen three digital certificates used for desktop and Atom applications.
Editorial image credit: Poetra.RH / Shutterstock.com