Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Vaguely related, SSH VisualHostKey / randomart

https://medium.com/@elg0nz/what-are-ssh-fingerprint-randomar...



Sure. But equally attackable I fear. If the attacker knows that you are just veryfing the visual appearance it should be much easier to brute force it and present something different that somehow looks similar enough that the difference is unlikey to be spotted.

Well, admittedly just a feeling. I have neither done the math nor any testing how big differences are likely to go undetected.

The best verification in openssh is to copy-paste the correct fingerprint as an answer instead of replying yes/no.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: