Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just for the record, Pastebin is not completely secure. Even private pastes can still be accessed if you know the URL - they aren't password protected like your account may be.

But like you said, if you posted the key alone anonymously, it will be hard to guess what lock it fits.



> Just for the record, Pastebin is not completely secure.

Note that it already happens that people put their private keys into pastebin, by accident or probably by sheer incompetence.

> if you posted the key alone anonymously, it will be hard to guess what lock it fits.

As an attacker, I would simply collect as many of those "published" private keys as I can get. Then, when attacking a bunch of systems, I'd simply try one key after another on each system.

The important difference to the "real world" is that an attacker can try lots of "locks" at once (i.e. can connect to multiple target systems at once).


When attacking a bunch of systems, I'd simply try one key after another on each system.

This was a good idea in 1990. But now you get IP-banned after three bad login attempts, so you have to be smarter.


Good point. However, that's what botnets are for. Why "wasting" those for distributed denial of service if you could break in instead?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: