3 ms·
Hmmmm. I don't know if I buy that. If the pattern is not cryptographically secure, then you're still vulnerable to man in the middle, and if it is cryptographic
by InvisibleCities 9y ago
Hmmmm. I don't know if I buy that. If the pattern is not cryptographically secure, then you're still vulnerable to man in the middle, and if it is cryptographically secure, wouldn't you get roughly the same security by just doing standard SSH key based auth?
- mannykannot 9y agoIsn't the point to have some defense in depth, so if there is a zero-day exploit found for your SSH authentication, you are not wide open? In a way like the grooves on a key for a pin-tumbler lock.