Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Infecting SSH Public Keys with Backdoors (thc.org)
3 points by philprx on May 24, 2023 | hide | past | favorite | 2 comments


Who password protect they private SSH keys? Many. Who reads their own ~/.ssh/* before using command? Nobody. Lateral movement even with protected private keys.


If using someone else’s public key, I always check the key itself (it doesn’t take long, and it is easy to spot “problems” like these).

This is a nice little hack, but I don’t see it flourishing in the wild.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: