3 ms·
One potential way to solve this would be to include the origin in the challenge, which the server could check: ssh demo-ssh.bob.com -l 7d7662f63f70de7714 -
by dlitz 11y ago
One potential way to solve this would be to include the origin in the challenge, which the server could check:
ssh demo-ssh.bob.com -l 7d7662f63f70de7714 -p 2222 https://www.bob.com
Mallory's attack then would have the possibility of being detected:
ssh demo-ssh.mallory.net -l 7d7662f63f70de7714 -p 2222 https://www.bob.com
However, this still relies on the user manually checking the origin of the challenge every single time, and users aren't very reliable. It might be better suited to a browser extension than to a manual copy-and-paste process.