4 ms·
Maybe I am missing something, but wouldn't this be vulnerable to a man in the middle attack?
by InvisibleCities 9y ago
Maybe I am missing something, but wouldn't this be vulnerable to a man in the middle attack?
- solotronics 9y agonot if the sequence changes based on some predetermined pattern
- InvisibleCities 9y agoHmmmm. I don't know if I buy that. If the pattern is not cryptographically secure, then you're still vulnerable to man in the middle, and if it is cryptographically secure, wouldn't you get roughly the same security by just doing standard SSH key based auth?
- mannykannot 9y agoIsn't the point to have some defense in depth, so if there is a zero-day exploit found for your SSH authentication, you are not wide open? In a way like the grooves on a key for a pin-tumbler lock.
- quincunx 9y agoThat would cover a replay attack, but not a man in the middle attack (as the mitm would just intercept the new port knock pattern.)
- ShaneWilton 9y agoOnly in the case of naive port knocking. You can always generate the knocking sequence with something like TOTP to avoid replay attacks, while also detecting attempts at replaying a previous knock. Edit: Sorry I misread your comment as talking about replay attacks, not MITM'ing. I'm not an expert, but I believe MITM attacks are typically mitigated by performing the knock out of band over a covert channel (DNS, etc). AFAIK, there isn't really a way to prevent them entirely.
- icebraining 9y agoYes, relying on port-knocking as your only authentication layer is not recommended; it's useful as a "front gate" to some other system.