Oh SSH-it, what's my fingerprint? A Large-Scale Analysis of SSH Host Key Fingerprint Verification Records in the DNS

08/18/2022
by   Sebastian Neef, et al.
0

The SSH protocol is commonly used to access remote systems on the Internet, as it provides an encrypted and authenticated channel for communication. If upon establishing a new connection, the presented server key is unknown to the client, the user is asked to verify the key fingerprint manually, which is prone to errors and often blindly trusted. The SSH standard describes an alternative to such manual key verification: using the Domain Name System (DNS) to publish the server key information in SSHFP records. In this paper, we conduct a large-scale Internet study to measure the prevalence of SSHFP records among DNS domain names. We scan the Tranco 1M list and over 500 million names from the certificate transparency log over the course of 26 days. The results show that in two studied populations, about 1 in 10,000 domains has SSHFP records, with more than half of them deployed without using DNSSEC, drastically reducing security benefits.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/07/2023

The Effect of Length on Key Fingerprint Verification Security and Usability

In applications such as end-to-end encrypted instant messaging, secure e...
research
08/21/2003

Fingerprint based bio-starter and bio-access

In the paper will be presented a safety and security system based on fin...
research
09/19/2023

A First Look at SVCB and HTTPS DNS Resource Records in the Wild

The Internet Engineering Task Force is standardizing new DNS resource re...
research
01/12/2021

Masking Host Identity on Internet: Encrypted TLS/SSL Handshake

Network middle-boxes often classify the traffic flows on the Internet to...
research
06/14/2010

An Effective Fingerprint Verification Technique

This paper presents an effective method for fingerprint verification bas...
research
08/26/2020

Server-side Fingerprint-Based Indoor Localization Using Encrypted Sorting

GPS signals, the main origin of navigation, are not functional in indoor...
research
06/26/2019

Secure Client and Server Geolocation Over the Internet

In this article, we provide a summary of recent efforts towards achievin...

Please sign up or login with your details

Forgot password? Click here to reset