RoyalMail,

True that ssh does "secure" communication, I had read the man pages for ssh, a way back, and didnt want to "give out" false information, so... Here are some, excerpts of the man pages:

Code:
ssh (SSH client) is a program for logging into a remote machine and for
     executing commands on a remote machine.  It is intended to replace rlogin
     and rsh, and provide secure encrypted communications between two
     untrusted hosts over an insecure network.  X11 connections and arbitrary
     TCP/IP ports can also be forwarded over the secure channel.

     ssh connects and logs into the specified hostname (with optional user
     name).  The user must prove his/her identity to the remote machine using
     one of several methods depending on the protocol version used.
Here is where it gets tricky... It all depends on what method, that will depend on what "secure" is...

SSH protocol version 1 (First example)
... This form of authentication alone is normally not allowed by
the server because it is not secure.


Most of the time, when you want to connect two systems, remotely, chances are, as I did, you will go with the RSA method. This is explained, and examples given, within the man pages for ssh, and what, I think, RoyalMail, was describing. It provides a form of "trust", over a "secure" connection, under "untrusted" lines, and such. The two systems "communicate", to each other, different forms of a "key". One part of the "key" is provided by the "server", and only known by the "server", the other part, from the "client", both parts of the "key" are then "put together" to form the "correct key", that "completed key", is then tested for "access" to the "server". All of this, is done encrypted, and again, each systems doesnt contain the whole key, thus, no one can "fake" any part of the key. This kind of secure connection, can be seen as a "safety box" at a bank. Where one person has one key, and the bank, has the other key. The box can not be openned, unless both keys are inserted, and the correct keys.

As with any connection, remotely, secure, or not, keeping your keys safe, is paramount. When I went through the setting up of ssh on my own two systems, I had to "copy" a key, from one system to the other. My guess here, is, that, if an "attacker" can obtain that "copy" as well, they could also gain "trusted" access, as well. My thinking is, if the system isnt "secure" in the first place, using a "secure" remote connection, will only allow an "untrusted" connection, with a "trusted" access, which, may, only add insult to injury, when trying to make a "secure" system. To re-use my previous analogy; if the bank allowed everyone access to the "banks key", the security of the safety box is in jeopardy, if the user allowed everyone access to the "personal key", the same holds true.

Just my thoughts,
Ms. Cuddles