4 ms·
https://www.usenix.org/system/files/login/articles/105484-Gutmann.pdf https://www.usenix.org/system/files/login/articles/105484-Gu... + People just don't check
by looofooo0 2y ago
https://www.usenix.org/system/files/login/articles/105484-Gutmann.pdf https://www.usenix.org/system/files/login/articles/105484-Gu... + People just don't check ssh keys normally.
- yjftsjthsd-h 2y agoThat's about host keys, not user keys. And... I'm struggling to think of a threat model where that problem manifests in a compromise? Like, what's your threat model? That said, CAs actually really help with that problem, because if a server has its host keys signed with a CA and then the user trusts that CA then they don't have to TOFU the host keys.