Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8070029
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 5, 20262026-06-05T13:15:47+00:00 2026-06-05T13:15:47+00:00

According to http://en.wikipedia.org/wiki/Secure_Shell#Key_management , ssh is vulnerable to man-in-the-middle attack when establishing the first

  • 0

According to http://en.wikipedia.org/wiki/Secure_Shell#Key_management, ssh is vulnerable to “man-in-the-middle” attack when establishing the first connection with server.

SSH also supports password-based authentication that is encrypted by automatically generated keys. In this case the attacker could imitate the legitimate side, ask for the password and obtain it (man-in-the-middle attack). However this is only possible if the two sides have never authenticated before, as SSH remembers the key that the remote side once used.

Does VPN suffer from the same “weakness”?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-05T13:15:49+00:00Added an answer on June 5, 2026 at 1:15 pm

    If VPN server is authenticated using the key which is known to the client, then there’s no problem – the key is already known (and supposedly trusted) and the client can be sure that it has connected to the legitimate server.

    The same applies to SSH. Wording in wikipedia is not exactly correct – for the first connection to be reliable the client should know the valid server key. It’s not important if “they have authenticated before”. It’s important that the client trusts the key.

    How can the key be trusted on the client? When X.509 certificate is used in SSL/TLS, it’s validated according to sophisticated rules and the certificate chain is built up to the trusted root certificate. If the chain can’t be built, then the end-entity certificate is not trusted. In SSH there are no certificate chains and the only way the client can trust the server is when the client has server’s key transferred using some other mechanism (voice call or paper or USB stick or separate SSL/TLS connection, whatever).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

According to http://en.wikipedia.org/wiki/Producer-consumer_problem I want to simulate P/C problem using semaphore. I am getting
I am new to python and graphics but have programmed before. According to http://en.wikipedia.org/wiki/Transformation_matrix#Rotation
According to wikipedia! http://en.wikipedia.org/wiki/ORDBMS IBM's DB2, Oracle database, and Microsoft SQL Server, make claims
I'm working on coloring a map according to the four-color theorem ( http://en.wikipedia.org/wiki/Four_color_theorem )
According to http://en.wikipedia.org/wiki/Comparison_of_Subversion_clients the web interface iF.SVNAdmin can be installed on a linux OS.
According to wiki http://en.wikipedia.org/wiki/Extensible_Messaging_and_Presence_Protocol , xmpp is using http binding (rather an http pooling)
According to the Wikipedia site: http://en.wikipedia.org/wiki/Volatile_variable I copied its sample code for testing in
According to http://en.wikipedia.org/wiki/Heap_%28data_structure%29#Comparison_of_theoretic_bounds_for_variants , it takes Θ(logn) (which translates to O(logn)) to perform the
According to this page http://en.wikipedia.org/wiki/RSA_numbers each RSA version uses one single constant long number
According to http://en.wikipedia.org/wiki/CUDA , Maximum x- or y-dimension of a block 1024 Maximum z-dimension

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.