GitHub Updates RSA SSH Host Key Following Exposure
GitHub updates RSA SSH host key after private key exposed in public repository
Customers using ECDSA or Ed25519 keys do not need to take action, but those using RSA need to update their ~/.ssh/known_hosts file
GitHub has yet to introduce a mechanism for revoking SSH keys, which could be a potential issue if compromised
Having a real-world risk/threat model is crucial for building reasonable security controls
Git authors should sign their commits with their own private key for code integrity, rather than trusting hosting providers
GitHub accidentally published its key, undermining the principle of trust and leaving all communications since its inception compromised
GitHub is encouraging improvements to certificates used for logging into code repositories
GitHub and GitLab both support two-factor authentication (2FA) via their command line interfaces (CLI)
The recent incident highlights potential security flaws in many fintech companies, including blind trust in GitHub host keys
GitHub briefly exposed a private key due to an accident, but took proactive measures to revoke and redeploy new keys and certificates, and implement enhanced controls.
US Court Bans Internet Archive's Book Lending Program
Internet Archive (IA) violated copyright law in lending digital copies of copyrighted books without permission according to a US judge ruling
IA argued it was exempt due to "fair use" but the judge found nothing transformative about their copying and lending of books
IA has been ordered to stop distribution of copyrighted books without permission
Court case brought by Hachette, HarperCollins, and Penguin Random House publishers against IA's scanning and digital lending practice
IA will comply with court's order and end lending program
Decision likely to impact users who rely on IA for access to texts unavailable elsewhere, particularly those who find traditional libraries inaccessible.
Police Sue Rapper Afroman for Invasion of Privacy in Music Videos
Police officers who conducted a botched raid of rapper Afroman's home are suing him for invasion of privacy and emotional distress after he used footage of it in his music videos.
Afroman used footage recorded by his wife and house cameras as part of several music videos which were released online and posted content from the raid to his social media accounts.
The police officers allege that Afroman's actions were "willful, wanton, malicious, and done with conscious or reckless disregard" and claim that they have been subject to ridicule by the public.
Each officer is seeking damages of $25,000 per four counts.
UK Food Inflation Reaches Highest Rate Since 1977, Sparking Concerns
Food inflation in the UK rose to 18.2% in February, the highest rate since 1977 due to higher vegetable costs, rising price of grains, certain proteins, eggs and oil.
UK supermarkets are struggling with food scarcity, high energy costs and global supply chain issues, leading to empty shelves and price hikes.
Inflation in food prices is causing concern for vulnerable groups, with some people struggling to buy enough food.
Rising energy costs and supply chain disruptions are among the factors cited as pressing inflationary pressures causing food prices to rise in many countries.
The root cause of inflation is elevated energy prices, as energy affects the production and transportation, which affects the price of groceries.