5 ms·
There's a lot of talk about data confidentiality, but I would argue that the data you could get from any one endpoint would be useful for reconnaissance within
by mr_cyborg 9y ago
There's a lot of talk about data confidentiality, but I would argue that the data you could get from any one endpoint would be useful for reconnaissance within its own peer neighborhood, and not much else, but I welcome use cases where I'd be wrong.
Additionally, downloading a client without getting the public key for the server won't help you - you can't just connect to any server you find. The author then links to a KB article about generating a different key than the one he would need anyway.
Relying on any vendor's documentation for proof of anything is the first mistake this author made. Giving himself an out by not actually trying any of these things, or weighing drawbacks against the benefits, means this is little more than speculative clickbait.
- geofft 9y ago> Additionally, downloading a client without getting the public key for the server won't help you - you can't just connect to any server you find. Right. The fact that the client is publicly accessible is a point in the vendor's favor, if anything: the fact that this "auditor" seems to think security-by-obscurity is a good idea makes me question why I bothered to read any of it.