3 ms·
Fair! When I last harassed Crawshaw about this and we discussed bits, he submitted https://github.com/C2SP/C2SP/blob/main/well-known-ssh-hosts.md https://githu
by raggi 2mo ago
Fair!
When I last harassed Crawshaw about this and we discussed bits, he submitted https://github.com/C2SP/C2SP/blob/main/well-known-ssh-hosts.md https://github.com/C2SP/C2SP/blob/main/well-known-ssh-hosts....
Unfortunately neither of us has taken time (AFAIK) to go back and implement it anywhere.
- tptacek 2mo agoI don't understand the impulse behind these things --- this is a bootstrap mechanism for a global PKI for SSH. But cold introductions to SSH hosts (that is, first connections to hosts you have no business or technical relationship with) virtually never happen. What problem does it solve?
- raggi 2mo agoWhen you see people advertising a coffee shop at a conference and people TOFU'ing on conference wifi then plugging in credit card numbers, the picture gets a little more clear.
- edmccard 2mo agoDo people at conferences buy coffee by SSH'ing into coffee shop servers?
- raggi 2mo agoi've seen it, so the answer is non-zero
- tptacek 2mo agoRight, I mean, I see the problem for browsers! Just not for SSH servers. (Capturing sessions like this used to be a contest at Usenix Security).
- raggi 2mo agoSo really the trend I'm talking about here is people turning SSH into a browser, hosting apps behind SSH that expect a much higher volume of TOFU happening, which is a departure from the "first time i setup my vps" kind of case. Honestly at this point I'd be kind of happy if we could just use an x.509 cert from a webpki acme provider in the sshd and be done with it, for the host identity part.