What is the randomart image for?
bytes.zone
bytes.zone
How computationally expensive is it to generate a key with randomart that kinda-resembles a known randomart?
I've always ignored randomart since I always assumed it's easy to get a close-enough "collision".
EDIT: algorithm explained here https://pthree.org/2013/05/30/openssh-keys-and-the-drunken-b...
The neat trick is that it's others of magnitude harder to find a key that kinda-resembles a known key and kinda-resmbles it's randomart, so if both are presented at the same time, you'd be safer.
Yes, it follows other slides that describe precisely the attack in TFA, only for traditional SSH fingerprints, and the real world surveys on the "how many users have called or emailed to verify the SSH key fingerprint whenever the key changed?" question (answer: literally zero), so it seems sadly accurate.
I often compare SHA256 sums of software and have to trust my eyes that the two hashes are the same. Most of the time I just look at the first 5 characters, alongside the last five characters, but I don't look at the middle, and I really should.
Some hashes could deliberately look the same but have 2-3 characters different, and I wouldn't know, unless I look at each character individually, but who does that?
$ echo hi > some_file
$ shasum -a 256 some_file > check
$ cat check
98ea6e4f216f2fb4b69fff9b3a44842c38686ca685f3f55dc48c5d3fb1107be4 some_file
$ shasum -a 256 -c check
some_file: OK
$ echo $?
0
$ echo bye > some_file
$ shasum -a 256 -c check
some_file: FAILED
shasum: WARNING: 1 computed checksum did NOT match
$ echo $?
1
Edit: Oh cool, at least perl's shasum allows reading from stdin so you can even skip the file if you're just copying some check file off the software's website: $ shasum -a 256 -c - <<EOF
> 98ea6e4f216f2fb4b69fff9b3a44842c38686ca685f3f55dc48c5d3fb1107be4 some_file
> EOF
some_file: OK hash="4e575a5ee4af2925477c9eea887ff560d23a586dbaf90b616d26c47ec429ca13"
[[ "$hash" == "$(shasum -a 256 file | awk '{print $1 }')" ]] && echo "Valid" || echo "Invalid checksum"
I use that little if-statement in some build systems. echo '98ea6e4f216f2fb4b69fff9b3a44842c38686ca685f3f55dc48c5d3fb1107be4 some_file' | sha256sum -c
also works (with and without passing `-n` to echo, because the `-c` option ensures the file is checked without even noticing any new line). Thanks :)When people claim they wrote a prediction at some later date, they always have to document the EXACT command used to avoid this, e.g. `echo "smart prediction" | md5sum`
This might be a cool contribution to coreutils (which contains the `sha256sum`, `sha1sum`, `md5sum`, ... programs)
(The term comes from https://en.wikipedia.org/wiki/Blink_comparator and someone wrote about this in a tech context as well, but I forgot where I read it. I'm seeing one search hit with the exact expression, so it could have been something close as well.)
Heck, most editors even come with a “compare selection with clipboard” option.
If someone uses "the keys never change" as an argument against this, I think they have completely missed the point. (Not saying OP has).
The random art is intended for _first time_ connections, where OpenSSH has to trust your judgement of the key's legitimacy because it has never connected to that host before.
It's not like it will hurt anything, but turning it on for every connection doesn't make a security difference.
https://en.m.wikipedia.org/wiki/Identicon
See some github repos:
Thank you for this:
and it turns out it worked! For example, I've started seeing the GitHub fingerprint (above) as something like the Statue of Liberty if it were a cat (don't ask why; that's just how my brain sees it)
Lol I’m switching this thing on!