Skip to content

Comment on Private key redaction: Ur doin it rong (2020)parent

Comments

This has the issue stated at the bottom of the article: someone will eventually copy that as their own private key, even if the author had never used it.

While I understand the sentiment, like all attempts at outsmarting stupid people, it is misplaced. If they're not copying your fake private key they're just copying someone else's.

In that case, just retract _any_ part of the key, such that it won’t work if you copy paste it, but still no used secret is revealed.

If a user wants to rebuild the key in order to use it for something, then they must have a very good reason to do so, and it is probably better to just let them do that.

Posting a screenshot instead of actual text is likely to work in this case, too, even if it's the whole key.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.