Users with weak SSH keys had access to GitHub repositories for popular projects

GitHub revoked the keys, but it's not clear if they were ever abused by attackers

A number of high-profile source-code repositories hosted on GitHub could have been modified using weak SSH authentication keys, a security researcher has warned.

The potentially vulnerable repositories include those of music streaming service Spotify, the Russian Internet company Yandex, the U.K. government and the Django Web application framework.

Earlier this year, researcher Ben Cox collected the public SSH (Secure Shell) keys of users with access to GitHub-hosted repositories by using one of the platform's features. After an analysis, he found that the corresponding private keys could be easily recovered for many of them.

The SSH protocol uses public-key cryptography, which means that authenticating users and encrypting their connections requires a private-public key pair. The server configured to accept SSH connections from users needs to know their respective public keys and the users need to have the corresponding private keys.

If a strong algorithm and a sufficiently large key size is used, it shouldn't be possible to recover a private key from a public key. However, that wasn't what Cox found for a "very large" number of GitHub users, some of whom had SSH access to some large and popular software projects.

The researcher collected 1,376,262 public SSH keys from GitHub and determined that 97.7 percent of them used the RSA algorithm. For RSA, the currently recommended size is 2048 bits, while the strength of 1024-bit keys is debatable and they are in the process of being deprecated.

Cox determined that 93.9 percent of the RSA-based public SSH keys he found on GitHub had 2048 bits, and around four percent had 1024 bits. He found 2 keys that had only 256 bits and 7 that had 512 bits, which would have been easy to break.

However, those small-sized keys were not the biggest problem. He found many other keys that were weak because of a bug in the OpenSSL package distributed with Debian Linux that was identified and patched in May 2008.

The bug was introduced in September 2006 and affected the source of randomness used by the random number generator when generating keys. Because of the flaw, any SSH and SSL keys created on Debian during that 20-month period had only 32,767 possibilities for every CPU architecture, key size, and key type.

Because it was easy for attackers to exploit this situation and break into systems using legitimate user accounts, the Debian developers and the security research community advised everyone who was possibly affected at the time to regenerate their keys.

However, it seems that a lot of people didn't listen and those weak keys are still used today, which is what Cox found when he compared the keys he gathered from GitHub to a key blacklist based on the Debian bug.

"The most scary part of this is that anyone could have just looped through all of these keys just trying to SSH into GitHub to see the banner it gives you," Cox said Tuesday in a blog post. "It would be safe to assume that due to the low barrier of entry for this, the users who have bad keys in their accounts should be assumed to be compromised and anything that allowed that key entry may have been hit by an attacker."

In addition to their own repositories, some of the users with weak keys had access to third-party projects including "Spotify's public repos, Yandex's public repos, crypto libraries for Python, Python's core, Django, gov.uk public repos, Couchbase and a ruby gem that is used on a large amount of CI systems," according to Cox.

Cox said that GitHub was notified and revoked the keys affected by the Debian bug in early May and other low-quality keys in early June.

"If you have just/as of late gotten an email about your keys being revoked, this is because of me, and if you have, you should really go through and make sure that no one has done anything terrible to you, since you have opened yourself to people doing very mean things to you for what is most likely a very long time," Cox said in his blog post.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags intrusionGitHubsecurityAccess control and authenticationencryption

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Crucial Ballistix Elite 32GB Kit (4 x 8GB) DDR4-3000 UDIMM

Learn more >

Gadgets & Things

Lexar® Professional 1000x microSDHC™/microSDXC™ UHS-II cards

Learn more >

Family Friendly

Lexar® JumpDrive® S57 USB 3.0 flash drive 

Learn more >

Stocking Stuffer

Plox Star Wars Death Star Levitating Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?