No SSHFP record, TOFU clients. This is not secure.<p>I wish people would stop trying to use SSH for things like this. PKI has features that are missing here and those features matter.<p>This is unsafe.<p>"but raggi, mitm before tofu is a really unrealistic scenario"<p>ok, well, consider that some large percentage of gas stations in the US have hardware installed to skim your credit cards. those same folks are perfectly well motivated to drop a wifi dns mitm in conference buildings (trivial). new tech conference, handful of credit cards as people gossip about exactly these kinds of things in the hallway track. the roi on these installs would be pretty high, because tech folks tend to have a high credit balance. so yeah, "totally unrealistic" (this is more about terminal.shop, but same principle here as soon as someone uses it for actual value).