DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Stop MITM on the first SSH connection, on any VPS or cloud provider

Quality: 9/10 Relevance: 9/10

Summary

This article presents a cloud-init-based technique to stop MITM on the first SSH connection to a new VM across VPS/cloud providers by injecting a temporary host key and then rotating to the long-term keys. It includes a threat model and security analysis, discusses key management, and provides implementation details and code references. It highlights provider-agnostic applicability and potential risks associated with cloud-init userdata exposure.

🚀 Service construit par Johan Denoyer