6 ms·
Presumably you would have to connect to a malicious host to be effected? Or perhaps a MITM on your connection to a legit host can exploit you somehow.
by doogle88 11y ago
Presumably you would have to connect to a malicious host to be effected? Or perhaps a MITM on your connection to a legit host can exploit you somehow.
- masklinn 11y ago> Presumably you would have to connect to a malicious host to be effected? Malicious or compromised. > roaming code in the ssh client could be tricked by a hostile sshd server, potentially leaking key material.
- amatix 11y agoFrom the updated OP: > The authentication of the server host key prevents exploitation by a man-in-the-middle, so this information leak is restricted to connections to malicious or compromised servers.
- jon-wood 11y agoMalicious, compromised, or new servers. Because really, how many people check the host key for a newly spun up EC2 instance?