logoalt Hacker News

kpcyrd04/03/20251 replyview on HN

There is nothing that can be done beyond what they are doing?

You can receive their public keys out-of-band through an https-authenticated connection. Which means their approach to "the initial trust problem" is _not_ "trust on first use".


Replies

squiggleblaz04/03/2025

I don't know what other solutions there are to TOFU, but maybe it's nice if there's something like a standardised /.well-known/ssh-keys.json path for public ssh servers like github and pico.sh.

show 1 reply