3 ms·
Just to be clear mbreese is talking about if you have just set up a new server like a vps and when you first ssh/scp to the server you accept a compromised key
by wortiz 16y ago
Just to be clear mbreese is talking about if you have just set up a new server like a vps and when you first ssh/scp to the server you accept a compromised key such as through a MITM attack but as he said this is highly unlikely to occur.
- fragmede 16y agoI setup a VPS on Linode, and they actually added the SSH RSA/DSA key for the 'admin console' login (Lish) when I asked about it on IRC. So, for first-time setup, you can lookup _that_ key, then from there, lookup the system key itself. This avoids a compromised key, at least from you to Linode. Hopefully Linode doesn't have any internal gremlins. Of course, the weak point there is SSL where the keys themselves are transmitted, but it did well to quell my paranoia.