KIT | KIT-Bibliothek | Impressum | Datenschutz

Fix it - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations

Hennig, Anne ORCID iD icon 1; Neef, Sebastian 2; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)
2 Technische Universität Berlin (TU Berlin)

Abstract:

Misconfigured SSHFP records might lead to SSH users not carefully verifying host key fingerprints, making SSH connections vulnerable to Man-in-the-Middle attacks. To warn domain owners about SSHFP misconfigurations and the potential security implications, we conducted a 2 × 3 randomized controlled notification experiment. We sent notifications to n = 518 domain owners with misconfigured SSHFP records. Following up on contradictory results from related work, we investigated the effects of tool support. While we see that the sender of the notification itself has no effect, our results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. Furthermore, we analyzed domain owners’ responses
to our notification to identify reasons for (non-) remediation. While only 27% remediated the misconfiguration after our notification, we identified valuable explanations for individual remediation behavior in the responses we received (n = 52), supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account.


Preprint §
DOI: 10.5445/IR/1000186330
Veröffentlicht am 31.10.2025
Originalveröffentlichung
DOI: 10.1109/ACSAC67867.2025.00098
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 08.12.2025
Sprache Englisch
Identifikator ISBN: 979-8-3315-5719-5
ISSN: 0167-4048
KITopen-ID: 1000186330
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Kapil Singh, Gianluca Stringhini, Nick Nikiforakis
Veranstaltung Annual Computer Security Applications Conference (ACSAC 2025), Honolulu, HI, USA, 08.12.2025 – 12.12.2025
Verlag Elsevier
Seiten 1255–1271
Schlagwörter DNSSEC, SSHFP, SSH, misconfiguration, notification experiment, vulnerability notification
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page