function ec2_ssh
ssh -F ~/.ssh/ec2_config $argv
end
And then in the ec2_config file… StrictHostKeyChecking=no
UserKnownHostsFile=/dev/null function ec2_ssh
ssh -F ~/.ssh/ec2_config $argv
end
And then in the ec2_config file… StrictHostKeyChecking=no
UserKnownHostsFile=/dev/nullI don't know how EC2 instances work in detail, but I imagine there must be a way to get a hold of the host key via an API or something when it's deployed (or maybe at any point) so that integrity could be kept without creating annoyance. I'd be much more comfortable with a solution that, for example, queries AWS over HTTPS before every connection and updates the host key (if necessary).
The script is designed for ephemeral instances, where I don’t intend to ever connect to the instance again, so saving the host key doesn’t help anything. So, really, anyone not using this hypothetical API is just as vulnerable to such a MITM attack in my threat model.
I was in a secure environment, the question for the key appeared, I accepted the new key I sometimes erase known_hosts, change keys etc. so it was not suspicious). And could not log in.
It took me some time to realize that the IP I was trying to connect is not mine (as in "at home") but on the company network. I realized that when I recalled that I had the key prompt.
I don't believe that it makes you vulnerable to MitM attacks if you are authenticating with a key.
https://security.stackexchange.com/questions/67242/does-publ...
function ec2_ssh
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null $argv
end