logoalt Hacker News

washingupliquidyesterday at 9:58 PM1 replyview on HN

I'm supposed to believe MitM with the same exact keypair is somehow possible? Private keys are never exchanged. Did everybody forget how crypto works?

Yes you implicitly trust the public key on first login.... then just... immediately compare it with what's on your box?

Might as well seal your doors with duct tape to prevent ghosts from entering your home because this is equally effective.


Replies

leni536yesterday at 10:31 PM

How do you compare? What trusted channel do you use to retrieve the real public key?