From 756869992055e4ae5e52f90efe7e86f6a4f014ac Mon Sep 17 00:00:00 2001 From: forest Date: Sun, 31 Jan 2021 02:16:13 -0600 Subject: [PATCH] clearly specify that its about the default ssh config --- capsulflask/templates/about-ssh.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/capsulflask/templates/about-ssh.html b/capsulflask/templates/about-ssh.html index 82b9a4d..b6e5509 100644 --- a/capsulflask/templates/about-ssh.html +++ b/capsulflask/templates/about-ssh.html @@ -318,8 +318,8 @@ Host key verification failed.

Because of the case for absolute simplicity, I think if anything, it might even make sense to remove the TOFU and make the ssh client even less user friendly; requiring the - expected host key to be passed in on every command would dramatically increase the security of real-world SSH usage. - This might already be possible with a custom SSH client configuration. + expected host key to be passed in on every command by default + would dramatically increase the security of real-world SSH usage. In order to make it more human-friendly again while keeping the security benefits, we can create a new layer of abstraction on top of SSH, create regime-specific automation & wrapper scripts.