Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can enforce public-key auth server-side, but you can't enforce that your clients won't prompt for a password if the (attacker-run) sshd a client connects to requires it.

Clients should be configured correctly to never ask. But many won't be and that's out of your control.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: