How to use Known-Hosts Change Comparer
- Supply the earlier known_hosts text and later known_hosts text using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the known hosts change comparer.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: Known-Hosts Change Comparer
Compare supplied host-key pin snapshots and highlight changed/added/removed keys. This example uses synthetic public data.
Options
- Before and after
- Keep all relevant records, including multiple key types and marker lines. A map with only one key per host can hide a meaningful change.
- Hashed hosts
- Hashed host identifiers are compared as entered. A different hash salt can prevent matching even when it names the same host.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
A changed pin needs investigation
A legitimate rotation, a changed endpoint or an unwanted key can all produce a difference. Confirm the expected key through an independent channel before accepting it. Hashed host fields are opaque here: only identical recorded identifiers can be matched, and the tool does not recover their hostnames.
Questions about Known-Hosts Change Comparer
Does a change mean an attack?
No. It identifies a change in the supplied pins and requires independent confirmation.
Can hashed hostnames be recovered?
No. They are compared opaquely without revealing their original names.
Are records updated automatically?
No. The page exports a review report and does not modify SSH files.