{"type":"rich","version":"1.0","author_name":"Dr. Hax (npub16v…meqha)","author_url":"https://nostr.ae/npub16v82nr4xt62nlydtj0mtxr49r6enc5r0sl2f7cq2zwdw7q92j5gs8meqha","provider_name":"njump","provider_url":"https://nostr.ae","html":"I just saw an attack in the wild. Fun!\n\nAn exit node is hijacking SSH traffic to github. The host fingerprint didn't match, the SSH key failed, and then it prompted for a password, which presumably would be harvested.\n\nI didn't spend much time on it, so I don't know if they patched their version of sshd to accept any password and then tie it to the repo that was pushed. That'd be smart.\n\nAnd I'm sure a reply-guy is going to jump in and say this is only a risk for Tor users, ignoring the fact that your ISP, their peers, and maybe a CDN can all pull off the same thing. And anyone who compromised any of these entities can do likewise.\n\nThis is alway a risk. It's why we have things like TLS for websites and host fingerprints to verify for SSH."}
