Skip to content

Infecting SSH Public Keys with Backdoors

blog.thc.org
3 pointsphilprx2 comments
On HN

Comments

Who password protect they private SSH keys? Many. Who reads their own ~/.ssh/* before using command? Nobody. Lateral movement even with protected private keys.

If using someone else’s public key, I always check the key itself (it doesn’t take long, and it is easy to spot “problems” like these).

This is a nice little hack, but I don’t see it flourishing in the wild.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.