upvote
Fair!

When I last harassed Crawshaw about this and we discussed bits, he submitted https://github.com/C2SP/C2SP/blob/main/well-known-ssh-hosts....

Unfortunately neither of us has taken time (AFAIK) to go back and implement it anywhere.

reply
I don't understand the impulse behind these things --- this is a bootstrap mechanism for a global PKI for SSH. But cold introductions to SSH hosts (that is, first connections to hosts you have no business or technical relationship with) virtually never happen. What problem does it solve?
reply
When you see people advertising a coffee shop at a conference and people TOFU'ing on conference wifi then plugging in credit card numbers, the picture gets a little more clear.
reply
Right, I mean, I see the problem for browsers! Just not for SSH servers. (Capturing sessions like this used to be a contest at Usenix Security).
reply
So really the trend I'm talking about here is people turning SSH into a browser, hosting apps behind SSH that expect a much higher volume of TOFU happening, which is a departure from the "first time i setup my vps" kind of case.

Honestly at this point I'd be kind of happy if we could just use an x.509 cert from a webpki acme provider in the sshd and be done with it, for the host identity part.

reply
Do people at conferences buy coffee by SSH'ing into coffee shop servers?
reply
i've seen it, so the answer is non-zero
reply