Reply to post: "The first time you log onto a server you get a signature"

'No questions asked' Windows code cert slingers 'fuel trade' in digitally signed malware

Anonymous Coward
Anonymous Coward

"The first time you log onto a server you get a signature"

Which is no more than a self-signed certificate. You can still play MitM. In a sound SSH implementation you don't rely on the key the server presents you on first access.

You're right with CAs - they cannot be simple commercial entities just selling certificates for profit. They should be bound to much higher standards and liable for their mistakes. Just, it will make certificates more expensive, and people instead want stuff for free.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon