Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At least an attacker (who doesn't have root) can't read a systems' SSH host keys.


Yes, client will notice that server fingerprint changed. So the question is, how many people will ignore that notice and still enter their password? SSH is a good software in that regard, as it allows clients to notice that server changed, but still it's an attack vector, one you should not just dismiss.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: