You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The ssh host key is created generated in the apt/deb script. So in case of this image at build time.
Using prebuilt images (from dockerhub) therefore is a security risk.
The text was updated successfully, but these errors were encountered:
Hi, thanks for the answer.
Problem with re-using host keys that are present in public builds is that there's no way to protect against MITM attacks. For some use cases this is no problem, for others it is.
It should just be clear from documentation. I personally just run my own builds to have my own host keys.
The ssh host key is created generated in the apt/deb script. So in case of this image at build time.
Using prebuilt images (from dockerhub) therefore is a security risk.
The text was updated successfully, but these errors were encountered: