1
If you have a good story involving any kind of common sense violation when it comes to SSH fingerprints, would you please share it to motivate future colleagues to do better? Examples of common violations I see in practice: not checking the fingerprint upon first use, ignoring the "remote host identification has changed" warning, only checking a part of the fingerprint optically (instead of typing/pasting the fingerprint), etc.
Thanks!