|
|
|
|
|
by eduction
1245 days ago
|
|
This attack makes no sense to me: ————— Active Attack: 1. Adversary replaces the contents of ./Personal/malicious-site.com with the contents of ./Work/id_ed25519 2. Victim decrypts ./Personal/malicious-site.com and the decrypted contents is placed in her clipboard automatically. 3. Victim logs into malicious-site.com. The victim just uploaded her work SSH private key to malicious-site.com ———— If the attacker is on the victim’s machine and has access to the ssh private key (“id_ed25519”), wouldn’t they just upload it directly to malicious-site.com via curl or whatever? Why this whole rigamarole? If someone is on your machine doing arbitrary things what software can reasonably protect you? Even Signal would fail. |
|
The attack works when the user doesn’t realize they’re sending their SHH private key through the password form of malicious-site.com.
Something like accidentally putting your Google password into the Dropbox login form. Dropbox have now seen your Google password.