TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

CVE-2022-46176: Cargo does not check SSH host keys

24 点作者 st_goliath超过 2 年前

2 条评论

rpigab超过 2 年前
I&#x27;m no security expert, and I know what I&#x27;m gonna say is bad, but I don&#x27;t find host key verification to be the most important part of securing client tools like Cargo, rather the opposite, to me, it&#x27;s the last thing you have to secure.<p>I believe the potential for attack only exists in a tiny specific case where the initial connection was trusted and successful, and an attacker goes through some trouble just to impersonate the server, when we forget one important thing, that the initial connection &quot;trust&quot; was extremely weak, like just prompt the user for confirmation, providing information that is shrugged off by 95% of users because they don&#x27;t know what to check or what is expected of them. So MITM could happen in the initial connection, and host key verification would have achieved nothing.<p>But it&#x27;s entirely possible that I&#x27;ve completely misunderstood this verification, because I&#x27;ve never really looked into it.
评论 #34349287 未加载
europeanguy超过 2 年前
Huh I was told that rust is safe...