BugTraq
SSH host key fingerprint - through HTTPS Sep 01 2014 04:41AM
John Leo (johnleo checkssh com) (3 replies)
Re: [FD] SSH host key fingerprint - through HTTPS Sep 01 2014 06:48PM
maxigas (maxigas anargeek net) (1 replies)
From: John Leo <johnleo (at) checkssh (dot) com [email concealed]>
Subject: [FD] SSH host key fingerprint - through HTTPS
Date: Mon, 01 Sep 2014 12:41:17 +0800

> This tool displays SSH host key fingerprint - through HTTPS.
>
> SSH is about security; host key matters a lot here; and you can know
> for sure by using this tool. It means you know precisely how to answer
> this question:
> The authenticity of host 'blah.blah.blah (10.10.10.10)' can't be
> established.
> RSA key fingerprint is
> a4:d9:a4:d9:a4:d9a4:d9:a4:d9a4:d9a4:d9a4:d9a4:d9a4:d9.
> Are you sure you want to continue connecting (yes/no)?
>
> https://checkssh.com/
>
> We hackers don't want to get hacked. :-) SSH rocks - when host key is
> right. Enjoy!

Excellent point and thanks for the tool! Indeed, fingerprint
verification is the absolute weak point of SSH. Here the problem
is that you have to trust the service operators when you use
checkssh or set up your own. Is the source code available
somewhere?

Also, a better solution is to use Monkeysphere which uses the
public key infrastructure of PGP. It can not just check your SSH
fingerprints automatically but do a whole lot of other things:

http://web.monkeysphere.info/

--
maxigas, kiberpunk
FA00 8129 13E9 2617 C614 0901 7879 63BC 287E D166
http://research.metatron.ai/

People the switches!

[ reply ]
Re: [FD] SSH host key fingerprint - through HTTPS Sep 02 2014 11:40AM
John Leo (johnleo checkssh com)
Re: SSH host key fingerprint - through HTTPS Sep 01 2014 03:16PM
Chris Nehren cnehren+bugtraq (at) pobox (dot) com [email concealed] (cnehren+bugtraq pobox com) (1 replies)
Re: SSH host key fingerprint - through HTTPS Sep 02 2014 06:38AM
Lukasz Biegaj (l biegaj netshock pl) (1 replies)
Re: SSH host key fingerprint - through HTTPS Sep 02 2014 10:50AM
Jamie Riden (jamie riden gmail com)
Re: SSH host key fingerprint - through HTTPS Sep 01 2014 11:41AM
Micha Borrmann (micha borrmann syss de) (1 replies)
Re: SSH host key fingerprint - through HTTPS Sep 02 2014 11:48AM
John Leo (johnleo checkssh com)


 

Privacy Statement
Copyright 2010, SecurityFocus