this post was submitted on 18 Sep 2024
47 points (92.7% liked)

Selfhosted

40296 readers
344 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

I had changed the SSH password on something so I had to dig through my known hosts file, and saw the word FUCK spelled out in there in all caps. I chuckled but am sure there's an explanation

all 24 comments
sorted by: hot top controversial new old
[–] variants@possumpat.io 44 points 2 months ago (1 children)

Nice try fbi you're not getting me that easy to give up my keys

[–] SidewaysHighways@lemmy.world 33 points 2 months ago

cmon man i aint never done nothin wrong with nobody's dang ssh keys. Jus lemme hold em

[–] bricklove@midwest.social 19 points 2 months ago (1 children)

I think I got "cunT" once and gave myself a heart attack because I thought I had accidentally committed a frustrated debugging log message to a work repo. I found it while searching for swears but it was in a file I hadn't changed

[–] 0x0@programming.dev 5 points 2 months ago

frustrated debugging log message

Just use porn actresses' names. Or so a friend told me...

[–] Drusenija@lemmy.world 16 points 2 months ago

We had a system at work that generated 4 character alphanumeric reference numbers. Originally to avoid this they just excluded vowels from the letters but eventually they grew enough they ran out of available reference numbers so they added the vowels back in and I had to built the blacklist to avoid stuff like this happening. I reckon I probably tripped every IT filter known to man in a week long period looking for swear words in a variety of languages 😂

[–] GBU_28@lemm.ee 15 points 2 months ago

That would be a rare, shiny PEM

[–] cybersandwich@lemmy.world 14 points 2 months ago (2 children)

I think you are obligated to share your entire known hosts file to prove this.

[–] SidewaysHighways@lemmy.world 25 points 2 months ago (2 children)
[–] bungle_in_the_jungle@lemmy.world 13 points 2 months ago (2 children)

Man this feels like deep lore at this point 😂

[–] 4am@lemm.ee 6 points 2 months ago (1 children)
[–] bungle_in_the_jungle@lemmy.world 4 points 2 months ago

Whaaaaat. I had no idea this had disappeared... sad news!

Thankfully it's archived at least: https://archive.is/BYZ9l

[–] Drusenija@lemmy.world 4 points 2 months ago

The part where people share asterisks when they talk about their passwords? Just seems like good security honestly 😂 Glad Lemmy is keeping up with this pinnacle of security best practices.

[–] tal@lemmy.today 9 points 2 months ago

The ~/.ssh/known_hosts file only contains public keys. I mean, maybe someone doesn't want to hand out the list of hosts that they talk to, but exposing it doesn't expose the private keys, which are what you really need to keep secret.

Those are in ~/.ssh/id_rsa or the like, depending upon key type.

[–] NorthWestWind@lemmy.world 13 points 2 months ago (1 children)

New blockchain just dropped

[–] InverseParallax@lemmy.world 4 points 2 months ago

Trump's coin dropped already.

[–] catloaf@lemm.ee 11 points 2 months ago (1 children)

The explanation is that it's random. Generate enough random strings and you're bound to get everything.

[–] SidewaysHighways@lemmy.world 3 points 2 months ago* (last edited 2 months ago) (1 children)

my old technology teacher told me about one time his ssh key was the whole soliloquy from hamlet.

~~then he turned himself into a fuckin pickle. craziest thing I ever seent~~

EDIT nvm?

[–] Couldbealeotard@lemmy.world 4 points 2 months ago

It was the best of times, it was the blurst of times!?

[–] gamma@programming.dev 8 points 2 months ago (1 children)

I know that "Vanity Addresses" are a common thing for onion sites, and there are tools which generate tons of keys looking for prefixes. I haven't seen such a tool for ssh host keys though.

[–] DaGeek247@fedia.io 2 points 2 months ago

They exist, but they're not nearly as fleshed out as the bitcoin vanity generators are. https://github.com/danielewood/vanityssh-go

[–] Grass@sh.itjust.works 5 points 2 months ago (1 children)

not particularly exciting I think I had 'dog' one time while distro hopping.

[–] 0x0@programming.dev 2 points 2 months ago

Should've been 'bunny'.

The explanation is pretty boring. If you look at https://superuser.com/questions/421997/what-is-a-ssh-key-fingerprint-and-how-is-it-generated it's explained that some fingerprints are displayed with Base64, which according to https://en.wikipedia.org/wiki/Base64 allows the use of all 26 letters of the alphabet, and both the complete uppercase and lowercase sets.

So basically it's just random chance that a given fingerprint has some data that shows up as a word.

SSH keys can likewise use base64, e.g. for PEM format, as per https://unix.stackexchange.com/questions/492704/what-encoding-is-used-for-the-keys-when-using-ssh-keygen-t-rsa