• Deathcrow
    cake
    arrow-up
    9
    arrow-down
    0
    ·
    7 months ago
    link
    fedilink

    or substituted its own SSH host keys,

    why would the backdoor do that? It would immediately expose itself because every ssh client on the planet warns about changed host keys when connecting.

    • gnuplusmatt
      arrow-up
      3
      arrow-down
      0
      ·
      7 months ago
      edit-2
      7 months ago
      link
      fedilink

      Perhaps it was a poorly worded way of suggesting that invalidating host keys would invalidate all client keys it could potentially generate? Either way it’s a lot of speculation.

      Resetting the keys and SSH config on any potentially compromised host is probably not a terrible idea