LWN.net Logo

The Web of Trust isn't better, it's just better than nothing

The Web of Trust isn't better, it's just better than nothing

Posted Mar 2, 2010 13:59 UTC (Tue) by robbe (guest, #16131)
In reply to: The Web of Trust isn't better, it's just better than nothing by nix
Parent article: Trust, but verify

> Unless you use only IP addresses when sshing everywhere, you're
> *already* trusting the root.

Am I? If I follow sound security practises (checking fp on new keys, not
ignoring the Big Scary Warning[TM]) all a malicious DNS can do is DOS me.

If you have HashKnownHosts disabled, you can even use known_hosts as a
poor man's directory service.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds