3 ms·
> it is not by default vulnerable to malicious CAs Well, in this particular case, they're using ssh [..] -o 'StrictHostKeyChecking no' -o 'UserKnownHostsFil
by lcampbell 12y ago
> it is not by default vulnerable to malicious CAs
Well, in this particular case, they're using
ssh [..] -o 'StrictHostKeyChecking no' -o 'UserKnownHostsFile /dev/null' [..]
So the remote authentication bits are already out the window. It would be nicer if they included the host's public key in the installation package rather than eschewing it completely.
- ambrop7 12y agoIndeed, they're just using it wrong.