4 ms·
> "using ssh as a transport mechanism for a web service is one of the worst practices you can use. SSL vulnerabilities are being spotted more frequently than ev
by lcampbell 12y ago
> "using ssh as a transport mechanism for a web service is one of the worst practices you can use. SSL vulnerabilities are being spotted more frequently than ever now"
Just wanted to note that SSH doesn't really have anything to do with SSL (e.g., it doesn't operate over an SSL transport). Might just be a typo though. Still seems really sketchy that they're using a reverse bind to (presumably) punch through NAT rather than something sane like just using UPnP or simply requiring correct network configuration.
- spacemanmatt 12y agoSeems like it's not a typo, rather he intended to indicate that he uses ssh due to SSL vulnerabilities precluding use of SSL.
- ambrop7 12y agoI see zero problem with using SSH, which happens to be a pretty secure protocol. In fact I would prefer it to HTTPS since it is not by default vulnerable to malicious CAs. Note for example that GitHub allows Git access over SSH. When the author says that the system "exposes the private key", well, it's by design that the user can see it - since they need to use it to identify themselves to the SSH server. It's not much different from being assigned a password by the server. What could be improved is if it was transferred over HTTPS rather than HTTP, and of course also the install script. (I only speak about the usage of SSH, it's possible that they still do something insecure..)
- lcampbell 12y ago> it is not by default vulnerable to malicious CAs Well, in this particular case, they're using ssh [..] -o 'StrictHostKeyChecking no' -o 'UserKnownHostsFile /dev/null' [..] So the remote authentication bits are already out the window. It would be nicer if they included the host's public key in the installation package rather than eschewing it completely.
- ambrop7 12y agoIndeed, they're just using it wrong.
- lucaspiller 12y ago> When the author says that the system "exposes the private key" To be fair the author didn't, the submitter did. I'm not sure if they are the same person.
- raverbashing 12y agoOh look, another "security expert" that doesn't know the difference between SSL and SSH Actually, SSH tunneling is a very secure way of transporting your web requests.
- nodata 12y agoIf you check the key. Which that script doesn't.
- raverbashing 12y agoI agree, that's the problem, the problem is not that it is SSH