Settings

Theme

Encrypted copies of Bitbucket SSH keys leaked

bitbucket.org

2 points by dentarg 3 years ago · 3 comments

Reader

necovek 3 years ago

Title made it confusing: how did bitbucket even have users' SSH keys?

However, it seems to be about their host keys. The article seems down for me, but https://bitbucket.org/blog/ has a title "ACTION REQUIRED: Update your Bitbucket Cloud SSH Host Keys".

That means that you need to drop their entries from your known_hosts file or you risk a MITM attack on an insecure network.

Considering we usually blindly accept new SSH hosts without checking for fingerprints (eg on new or reinstalled machines), it's probably unlikely this will be exploited in the wild since it already could have been.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection