4 ms·
The procedure for credential reset sounds a little concerning: > are you a town resident that lost their ssh key? try this: using the email address with which
by vnorilo 4y ago
The procedure for credential reset sounds a little concerning:
> are you a town resident that lost their ssh key? try this: using the email address with which you registered, send an email to root@tilde.town. put "new public key" in the subject. include the new public key in the body of the email
Hopefully they will at least reply to confirm the person can actually read the email instead of just replacing pubkeys from any forged from-address.
- Affric 4y agoIt does seem like they read the emails. A reminder that the web can be social.
- vnorilo 4y agoReading the emails is not enough: they would need to send some secret to the email associated with the account to link the power to exhange keys to ownership of the account. Just reading a legit-sounding email and relying on from-address is 100% suspectible to abuse.
- mccorrinall 4y agoUsually your email doesn’t even make it into the spam folder but just gets straight rejected if the DKIM signature isn’t valid. Unless the admin doesn’t know how to run an email server in 2022.
- 8organicbits 4y agoIt's also worth considering threat models. It may be worth risking account takeover if they can keep the reset flow user friendly. Not every site needs bulletproof security, this one seems lower risk.
- hnlmorg 4y agoThis is a operation for people to have little sandboxes for fun. Not only is the threat model signify lower than your average social network but the blast radius too. It’s also worth noting that there’s a multitude of ways one could take over these machines if they were determined enough. The entire principle behind this is giving people shell access for giggles. So we aren’t exactly taking about VPSs for serious business here. While security is always important for anything online, it’s also important that security is balanced against appropriateness. Here the point is a little slice of the old days even though that does invite some risk.
- lupire 4y agoIf the person can't read the email, then they can't read the key. This is exactly how credential reset works on every system with registered backup email address, include Google. The only risk is if they send the key to the wrong email address, such as From and Reply-To.
- lights0123 4y ago> If the person can't read the email, then they can't read the key. You’re sending them your public key, not receiving a private key.