Re: Any way to decrypt hashes set by ssh HashKnownHosts?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



eliott schrieb:
Just because you can't see it doesn't mean it doesn't exist.
unhashed known_hosts *is* more unsecure.

If someone gets access to your account, they would get
a) your key
b) a list of hosts that the key is valid for

hey! great!

Compund this with the fact that many people use keys without a
passphrase (a bad practice), someone can 'harvest' known_host data,
and worm out to other hosts.. here is the kicker ... in a way that is
easily automated.

The point is, without any notice, we provided a different configuration file than the upstream configuration file. That's not how we do it, we always provide the upstream configuration file.

If someone thinks that having unhased known_hosts is a security problem, then he/she can change this configuration option on his/her system, that is how Arch works. But now that hashed known_hosts silently became the default, I cannot revert back.

Attachment: signature.asc
Description: OpenPGP digital signature


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux