Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Supplying an SSH public key for future login use

It's public so it can be emailed in cleartext to the admin of the server, copied in any instant messenger or painted on walls. It's the secret key that ensures all the security of the connection.



It still needs to be authenticated. It could be replaced by an attacker public key.


This is a scenario where "the humans can speak to each other (directly) but the computers cannot". Key authenticity is not a problem, the other party can verify that the fingerprint is correct.


True, but have you actually tried to verify even a short SSH pubkey over a human communication channel? It can be done, but the horrible, horrible UX!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: