TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Encrypted copies of Bitbucket SSH keys leaked

2 点作者 dentarg将近 2 年前

1 comment

necovek将近 2 年前
Title made it confusing: how did bitbucket even have users&#x27; SSH keys?<p>However, it seems to be about their host keys. The article seems down for me, but <a href="https:&#x2F;&#x2F;bitbucket.org&#x2F;blog&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;bitbucket.org&#x2F;blog&#x2F;</a> has a title &quot;ACTION REQUIRED: Update your Bitbucket Cloud SSH Host Keys&quot;.<p>That means that you need to drop their entries from your known_hosts file or you risk a MITM attack on an insecure network.<p>Considering we usually blindly accept new SSH hosts without checking for fingerprints (eg on new or reinstalled machines), it&#x27;s probably unlikely this will be exploited in the wild since it already could have been.
评论 #36531358 未加载