3 ms·
> I feel compelled to be "that guy" for a second and just mention that while this is convenient, it makes you blatantly vulnerable to man-in-the-middle attacks.
by ryan-c 4y ago
> I feel compelled to be "that guy" for a second and just mention that while this is convenient, it makes you blatantly vulnerable to man-in-the-middle attacks.
I don't believe that it makes you vulnerable to MitM attacks if you are authenticating with a key.
- deleted 4y ago[deleted]
- hnarn 4y agoWhy?
- ryan-c 4y agoThe server requests the client prove it holds the private key in a way that is bound to the session id, which is derived from the shared secret established with ephemeral key exchange. https://security.stackexchange.com/questions/67242/does-public-key-auth-in-ssh-prevent-most-mitm-attacks https://security.stackexchange.com/questions/67242/does-publ...