Once you leak your public key it could be used to check if another server recognizes that leaked public key.
Late.sh – a command-line Clubhouse for computer people
61–70 of 141 posts
Re: Late.sh – a command-line Clubhouse for computer people
#62Re: Late.sh – a command-line Clubhouse for computer people
#63Re: Late.sh – a command-line Clubhouse for computer people
#64Reminder to be cautious about leaking public keys. Once you leak your public key it could be used to check if another server recognizes that leaked public key.
Re: Late.sh – a command-line Clubhouse for computer people
#65Reminder to be cautious about leaking public keys. Once you leak your public key it could be used to check if another server recognizes that leaked public key.
What?
~/.ssh/id_ecdsa.pub
~/.ssh/id_ecdsa_sk.pub
~/.ssh/id_ed25519.pub
~/.ssh/id_ed25519_sk.pub
~/.ssh/id_xmss.pub
~/.ssh/id_dsa.pub
running `ssh late.sh` would do exactly that.At the very bottom of the website they give you a command that would not leak your public keys.
`ssh-keygen -t ed25519 -f ~/.ssh/late_throwaway && ssh -o IdentitiesOnly=yes -i ~/.ssh/late_throwaway late.sh`
this would only send the late_throwaway public key
Re: Late.sh – a command-line Clubhouse for computer people
#66Earlier quoted context omitted.
What?
By default SSH leaks all of the below public keys (if they exist) + all public keys in your ssh-agent to a server you connect to. ~/.ssh/id_ecdsa.pub ~/.ssh/id_ecdsa_sk.pub ~/.ssh/id_ed25519.pub ~/.ssh/id_ed25519_sk.pub ~/.ssh/id_xmss.pub ~/.ssh/id_dsa.pub running `ssh late.sh` would do exactly that. At the very bottom of the website they give you a command that would not leak your public keys. `ssh-keygen -t ed25519…
Re: Late.sh – a command-line Clubhouse for computer people
#67Earlier quoted context omitted.
By default SSH leaks all of the below public keys (if they exist) + all public keys in your ssh-agent to a server you connect to. ~/.ssh/id_ecdsa.pub ~/.ssh/id_ecdsa_sk.pub ~/.ssh/id_ed25519.pub ~/.ssh/id_ed25519_sk.pub ~/.ssh/id_xmss.pub ~/.ssh/id_dsa.pub running `ssh late.sh` would do exactly that. At the very bottom of the website they give you a command that would not leak your public keys. `ssh-keygen -t ed25519…
Okay, but why is that something to be concerned about? How would one be able to probe to see if a server recognizes a public key? Why does that matter?
Re: Late.sh – a command-line Clubhouse for computer people
#68Reminder to be cautious about leaking public keys. Once you leak your public key it could be used to check if another server recognizes that leaked public key.
Re: Late.sh – a command-line Clubhouse for computer people
#69Earlier quoted context omitted.
By default SSH leaks all of the below public keys (if they exist) + all public keys in your ssh-agent to a server you connect to. ~/.ssh/id_ecdsa.pub ~/.ssh/id_ecdsa_sk.pub ~/.ssh/id_ed25519.pub ~/.ssh/id_ed25519_sk.pub ~/.ssh/id_xmss.pub ~/.ssh/id_dsa.pub running `ssh late.sh` would do exactly that. At the very bottom of the website they give you a command that would not leak your public keys. `ssh-keygen -t ed25519…
Okay, but why is that something to be concerned about? How would one be able to probe to see if a server recognizes a public key? Why does that matter?