4 ms·
I tested this and on a new enough OpenSSH client, the RSA key gets replaced using the mechanism described here: https://lwn.net/Articles/637156/ https://lwn.net
by NieDzejkob 4y ago
I tested this and on a new enough OpenSSH client, the RSA key gets replaced using the mechanism described here: https://lwn.net/Articles/637156/ https://lwn.net/Articles/637156/ (if you connect using a key other than RSA).
To be honest, I'd expect something like this to be mentioned in the announcement.
- creamyhorror 4y agoAssuming the user connects to Github first instead of a MitM attacker spoofing Github.