Skip to content

Verify host keys for SFTP #544

Description

@zhanghai

Currently host key verification is just completely skipped, but maybe we should still at least ensure the fingerprint doesn't change after first connection.

Activity

  1. self-assigned this
    on Aug 5, 2021
  2. changed the title [-]Verify host keys in SFTP[/-] [+]Verify host keys for SFTP[/+] on Aug 5, 2021
  3. added a commit that references this issue on Aug 5, 2021
  4. FloX-Dev commented on Apr 21, 2024

    @FloX-Dev

    Hi, Given that this is a function that I think is absolutely necessary from a security point of view, would it be possible to have an ETA ?

  5. added this to the v1.8.0 milestone on Apr 22, 2024
  6. modified the milestones: v1.7.3, v1.8.0 on May 18, 2024
  7. modified the milestones: v1.7.4, v1.8.0 on Jun 28, 2024
  8. phantompatch commented on Jun 1, 2026

    @phantompatch

    Hello, I want to express my strong support for this change. Even presenting a simple confirmation dialog that displays the new fingerprint and requires user approval should be sufficient:

    • Cancel → Abort the connection.
    • Confirm → Update the stored fingerprint/public key and proceed.

    The dialog could also include a checkbox such as "I am sure the new fingerprint is trusted."

    Accepting any host key without verification is extremely risky and can enable man-in-the-middle attacks, allowing an attacker on the network to intercept, modify, or replace transferred files or even take over the connection after authentication.

    I consider this a serious security flaw in its current form.

    For reference, OpenSSH's confirmation prompt appears as follows:

    @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
    @    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
    @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
    IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
    Someone could be eavesdropping on you right now (man-in-the-middle attack)!
    It is also possible that a host key has just been changed.
    The fingerprint for the ED25519 key sent by the remote host is
    SHA256:[...].
    
  9. added a commit that references this issue on Jul 7, 2026
  10. added a commit that references this issue on Aug 28, 2026
    6c13bed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions