4 ms·
Registration over ssh is cute but not safe from MITM attacks. Even if the ssh key was published somewhere (which as far as I can tell it isn't) you would be dep
by helper 8y ago
Registration over ssh is cute but not safe from MITM attacks. Even if the ssh key was published somewhere (which as far as I can tell it isn't) you would be dependent on people manually adding the key to their known_hosts file which you can't reasonably expect most people to bother with.
- marci 8y agoYou can't reasonably expect most people who would register to a service over ssh and make backups with cUrl in a shell script to update their known_hosts file? The instructions on the main page would change from: ssh register@ui.baxx.dev to something like curl https://ui.baxx.dev/ssh_keys -o /tmp/baxx_ssh_keys cat /tmp/baxx_ssh_keys cat /tmp/baxx_ssh_keys >> ~/.ssh/known_hosts rm /tmp/baxx_ssh_keys ssh register@ui.baxx.dev or in one line: curl https://ssh_key.baxx.dev >> ~/.ssh/known_hosts && ssh register@ui.baxx.dev
- helper 8y agoThe author of this service didn't think it important to provide the ssh key and based on the comments in this thread people have already signed up for this service without caring about the key. So yes, I think even people who would use this service mostly can't be bothered to manually update their known_hosts file.
- marci 8y agoIn that sense then I agree with you. Edit: I thought you meant that, given the command, most would still not do it.
- zulgan 8y agoYou are right. it is super cute though, I still get excited every time I try the registration flow. the registration api is quite easy (https://baxx.dev/help/register https://baxx.dev/help/register) curl -d '{"email":"your.email@example.com", "password":"mickey mouse"}' \ https://baxx.dev/register I will probably do make register.sh endpoint that returns a bash script that runs local dialog like: curl https://baxx.dev/register.sh https://baxx.dev/register.sh | sh (just idea, not implemented yet) this will be fun, making portable tty dialogs :D