ssh clear text passwords?

Red Squirrel

No Lifer
May 24, 2003
69,943
13,463
126
www.anyf.ca
I saw this in the ssh config file:

# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication yes
#PermitEmptyPasswords no
PasswordAuthentication yes


So... if I have password authentication turned on, it's sent in clear text?! This can't be right,is it?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
It's sent in clear text inside of the established tunnel so it's not clear text on the wire.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Pretty much, if you want to be sure you can always break out a packet sniffer.