frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Stop MitM on the first SSH connection, on any VPS or cloud provider

https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection,%20on%20any%20VPS%20or%20cloud%20provider.html
15•JoachimSchipper•2d ago

Comments

londons_explore•56m ago
A big class of attacker is nation state attackers who do not want to risk discovery.

A big way to deter them is to keep remote log files which, if analyzed, will reveal any attack.

For example, if both ssh-client and ssh-server kept a fingerprint of the session key in some append-only logfile, then a later administrator could compare the logfiles to know if an MITM happened.

Suddenly, nation state attackers won't be interested in MITM-ing at all.

Unfortunately it appears openssh doesn't even have an option to create such a logfile!! Why not??

hnlmorg•45m ago
Couldn’t the MITM ssh server just forward the client’s fingerprint to the legitimate server?

If so, the legitimate server wouldn’t have anything in their logs that would help detect such an attack.

OpenSSH does log other telemetry though.

skydhash•47m ago
> The technique appears to be new: I haven't found a proper write-up of this, nor of any other provider-independent solution (but I'd welcome a correction).

To be frank, anyone that serious about security would probably log in via console, generate and retrieve the host key that way. And then any client would have strict verification enabled.

It's kinda the 101 of communication using public keys cryptography. You have to get hold of the public key in a secure manner first (direct contact or attestation by a third party).

Section 3.1 in Bruce Scheiner's Applied Cryptography discuss how to automatically solves MITM. But that's only important for M:N communications (TSL). For 1:1 communications where you can have secure exchange before hand, no need to go that far.

crypt0r84•22m ago
provision the hosts with an SSH CA, use the CA as a trust root in openssh. they are various version out there from the big players.
INTPenis•19m ago
The author essentially bootstraps their servers with a known trusted host key, so that first connection is recognized, instead of having to trust a new and recently generated host key when you first connect.

It's a neat little trick if you're often deploying VPS in shared cloud environments.

Hardware Attestation as Monopoly Enabler

https://grapheneos.social/@GrapheneOS/116550899908879585
285•ChuckMcM•1h ago•78 comments

Incident Report: CVE-2024-YIKES

https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html
125•miniBill•1h ago•29 comments

Traces Of Humanity

https://tracesofhumanity.org/hello-world/
66•alex77456•2h ago•10 comments

Lakebase architecture delivers faster Postgres writes

https://www.databricks.com/blog/how-lakebase-architecture-delivers-5x-faster-postgres-writes
50•sp_from_db•2d ago•9 comments

I returned to AWS and was reminded why I left

http://fourlightyears.blogspot.com/2026/05/i-returned-to-aws-and-was-reminded-hard.html
496•andrewstuart•1d ago•392 comments

Walking slower? Your ears, not your knees, might be the problem

https://www.wsj.com/health/wellness/hearing-loss-walking-speed-iphone-study-c53c482a
52•marc__1•1d ago•41 comments

Stop MitM on the first SSH connection, on any VPS or cloud provider

https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection,%20on%20any%20VP...
17•JoachimSchipper•2d ago•6 comments

What's a mathematician to do? (2010)

https://mathoverflow.net/questions/43690/whats-a-mathematician-to-do
116•ipnon•8h ago•61 comments

The Locals Don't Know

https://www.quarter--mile.com/The-Locals-Dont-Know
34•herbertl•3h ago•22 comments

Louis Rossmann offers to pay legal fees for a threatened OrcaSlicer developer

https://www.tomshardware.com/3d-printing/louis-rossmann-tells-3d-printer-maker-bambu-lab-to-go-bl...
288•iancmceachern•4h ago•177 comments

Idempotency is easy until the second request is different

https://blog.dochia.dev/blog/idempotency/
233•ludovicianul•3d ago•148 comments

Space Cadet Pinball on Linux

https://brennan.io/2026/05/09/pinball-and-escrow/
261•jandeboevrie•8h ago•89 comments

Spain just became one of Europe's cheapest power markets. Here is how

https://janrosenow.substack.com/p/spain-just-became-one-of-europes
64•marc__1•2h ago•42 comments

The One Dollar Counterfeiter

https://www.amusingplanet.com/2026/05/emerich-juettner-one-dollar.html
288•cainxinth•3d ago•121 comments

Show HN: An index of indie web/blog indexes

https://theindex.fyi
41•rocketpastsix•6h ago•16 comments

Show HN: Building a web server in assembly to give my life (a lack of) meaning

https://github.com/imtomt/ymawky
363•imtomt•16h ago•194 comments

Think Linear Algebra (2023)

https://allendowney.github.io/ThinkLinearAlgebra/index.html
114•tamnd•9h ago•12 comments

Shunting-Yard Animation

https://somethingorotherwhatever.com/shunting-yard-animation/
29•s1291•4h ago•11 comments

GitHub is sinking

https://dbushell.com/2026/04/29/github-is-sinking/
125•herbertl•3h ago•77 comments

9 Mothers (YC P26) Is Hiring

https://jobs.ashbyhq.com/9-mothers?utm_source=x8pZ4B3P3Q
1•ukd1•7h ago

Task Paralysis and AI

https://g5t.de/articles/20260510-task-paralysis-and-ai/index.html
132•MrGilbert•13h ago•81 comments

Decoding raw digital photos in Linux (1997)

https://dechifro.org/dcraw/
4•weinzierl•3d ago•0 comments

Casio S100X Japanese Lacquer Edition (JP Page Only)

https://www.casio.com/jp/basic-calculators/premium/en-s100x-jc1-u/
270•dr_kiszonka•3d ago•131 comments

Academic Research Skills for Claude Code

https://github.com/Imbad0202/academic-research-skills
63•arnon•5h ago•21 comments

The River Otter's Remarkable Comeback

https://www.rewildingmag.com/the-river-otters-remarkable-comeback/
65•surprisetalk•3d ago•13 comments

I’ve banned query strings

https://chrismorgan.info/no-query-strings
519•susam•1d ago•272 comments

We see something that works, and then we understand it

https://lemire.me/blog/2025/12/04/we-see-something-that-works-and-then-we-understand-it/
172•surprisetalk•4d ago•69 comments

Chrome's AI features may be hogging 4GB of your computer storage

https://www.theverge.com/tech/924933/google-chrome-4gb-gemini-nano-ai-features
59•birdculture•4h ago•30 comments

Gemini API File Search is now multimodal

https://blog.google/innovation-and-ai/technology/developers-tools/expanded-gemini-api-file-search...
140•gmays•16h ago•38 comments

A recent experience with ChatGPT 5.5 Pro

https://gowers.wordpress.com/2026/05/08/a-recent-experience-with-chatgpt-5-5-pro/
678•_alternator_•1d ago•509 comments