Hacker News new | past | comments | ask | show | jobs | submit login

It doesn't, but if someone is shelling around on the server, they might throw a key in there for convenience, maybe in order to scp something from another machine, and then forget to remove it when they're done.

One can debate whether the root cause is forgetfulness, or rather that people shouldn't be sshing into prod servers to begin with.




Ever putting private data in a public place, is an unacceptable risk. Even if you remember to remove it there is a window of vulnerability. And there are people out there constantly probing for weaknesses.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: