Repository navigation
Verify host keys for SFTP #544
Description
Activity
- added a commit that references this issue
on Aug 5, 2021 Hi, Given that this is a function that I think is absolutely necessary from a security point of view, would it be possible to have an ETA ?
- added a commit that references this issue
on Nov 12, 2025 Hello, I want to express my strong support for this change. Even presenting a simple confirmation dialog that displays the new fingerprint and requires user approval should be sufficient:
- Cancel → Abort the connection.
- Confirm → Update the stored fingerprint/public key and proceed.
The dialog could also include a checkbox such as "I am sure the new fingerprint is trusted."
Accepting any host key without verification is extremely risky and can enable man-in-the-middle attacks, allowing an attacker on the network to intercept, modify, or replace transferred files or even take over the connection after authentication.
I consider this a serious security flaw in its current form.
For reference, OpenSSH's confirmation prompt appears as follows:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed. The fingerprint for the ED25519 key sent by the remote host is SHA256:[...].- added a commit that references this issue
on Jul 7, 2026 - added a commit that references this issue
on Aug 28, 2026 - added a commit that references this issue
on Oct 6, 2026
Currently host key verification is just completely skipped, but maybe we should still at least ensure the fingerprint doesn't change after first connection.