back

by dcminter·9mo ago·view on hn ↗
I guess the interesting question to me is: how often does this matter? How many successful mitm attacks on ssh connections are there and in what sort of circumstances do they occur?

It seems like it ought to matter, but if roughly nobody verifies and yet the sky has not fallen - does it?

2 comments
It's only for the first connection, and it's very rare that targets are valuable on the first connection.

On the other hand, we know of at least two suppliers of software that run with elevated access everywhere (including the dev side of every advanced military) that have been breached by unknown parties for years. The most likely explanation, by far, is that the sky only didn't fall yet because nobody wants it to. And that leaves us vulnerable to somebody suddenly wanting it.

nobody robbed my house in years. i still lock the door.

it's so banal to check host keys.