|
|
|
|
|
by cntlzw
2714 days ago
|
|
I don't want to be cynical. There is probably lots and lots of work being put in this project, but.... The business idea is basically this: hand me your credit card, I go to your favorite ATM, get some money and hand it to you. It is great service! Yes, a great service for some, but why would I give the most sensible credentials I own to a third-party? SSH tries to avoid man-in-the-middle attack. This is a man-in-the-middle attack as a service. |
|
First, thanks for your brutality. It's good to know that a service like this (which deals with such sensitive content) is treated suspiciously at first.
Second, a few commenters have shown that it may be possible to reduce the MitM aspect by pushing more work into the browser with a method that could also provide end to end encryption. We're going to look into this thoroughly because we thought it was impossible at first, but I'm also curious if that would change your mind at all about using the service. At the very least, it would improve our users' security, so we're still going to see if we can do it.
Third, I do want to emphasize that we encourage users to create multiple keys to use, so that they have lots of power over granting and revoking server access via those keys (kind of like a new proxy credit card in your example, I guess). There are lots of ways a service like Shellvault could accidentally encourage poor habits, and we're working very hard to encourage good ones instead.
Thanks!