▲ | raggi a day ago | ||||||||||||||||||||||||||||||||||
So approximately nothing? | |||||||||||||||||||||||||||||||||||
▲ | junon a day ago | parent | next [-] | ||||||||||||||||||||||||||||||||||
Perhaps giving a bit more information than throwing out random acronyms related to SSH would be a bit more fruitful in terms of responses. What about TOFU and MITM would you like them to respond to? TOFU isn't inherently a bad thing. Neither is MITM. It depends on the threat model, the actors involved, etc. Your comment (and the snarky followup) imply they're doing something wrong, but it's unclear what. | |||||||||||||||||||||||||||||||||||
▲ | kpcyrd a day ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||
There is nothing that can be done beyond what they are doing? You can receive their public keys out-of-band through an https-authenticated connection. Which means their approach to "the initial trust problem" is _not_ "trust on first use". | |||||||||||||||||||||||||||||||||||
|