It's up to you to decide if it's okay that you send a server provider (in this case late.sh) a bunch of your public keys which he could for example use to probe other servers to see if you have access to them.
Everyone has different opsec.
477 karma · joined November 29, 2012
It's up to you to decide if it's okay that you send a server provider (in this case late.sh) a bunch of your public keys which he could for example use to probe other servers to see if you have access to them.
Everyone has different opsec.
~/.ssh/id_ecdsa.pub
~/.ssh/id_ecdsa_sk.pub
~/.ssh/id_ed25519.pub
~/.ssh/id_ed25519_sk.pub
~/.ssh/id_xmss.pub
~/.ssh/id_dsa.pub
running `ssh late.sh` would do exactly that.At the very bottom of the website they give you a command that would not leak your public keys.
`ssh-keygen -t ed25519 -f ~/.ssh/late_throwaway && ssh -o IdentitiesOnly=yes -i ~/.ssh/late_throwaway late.sh`
this would only send the late_throwaway public key
Once you leak your public key it could be used to check if another server recognizes that leaked public key.
Am I the one who is crazy and nitpicking here?
# UMASK is the default umask value for pam_umask and is used by
# useradd and newusers to set the mode of the new home directories.
# 022 is the "historical" value in Debian for UMASK
# 027, or even 077, could be considered better for privacy
# There is no One True Answer here : each sysadmin must make up his/her
# mind.Would it really be so hard to make that switch to a more privacy focused umask?
addEventListener('keydown', event => {
if(event.key !== 'Enter')
return
elementWithSelection = getSelection().anchorNode?.parentElement
if(!elementWithSelection)
return
elementWithSelection.click()
getSelection().empty()
})
This allows you to use the native CTRL+f and / search basically like the ' search.The ' search let's you "click" on links by pressing enter.
The snippet let's you do the same for the other searches too so you can navigate the modern web where often navigations and actions are behind buttons and sometimes even divs (not just links). Unfortunately you can't activate those without this little hack.
The extension will be available at https://addons.mozilla.org/en-US/firefox/addon/click-on-sele... soon (after mozilla approves).
I use this trick in a slightly bigger extension too https://github.com/h43z/jkscroll/blob/main/content-script.js...
I think what you are thinking of are dns rebinding attacks.
~/.ssh/id_ecdsa.pub
~/.ssh/id_ecdsa_sk.pub
~/.ssh/id_ed25519.pub
~/.ssh/id_ed25519_sk.pub
~/.ssh/id_xmss.pub
~/.ssh/id_dsa.pub
Your "leaked" public keys can be used to check if a certain server recognizes that key.