I often ssh into servers for work and play using dynamic dns with ssh keys that are password protected. Twice now (shame on me!) I have mistyped the dyndns.org part of the address and been greeted with several password prompts making me think id mistyped the password, before realizing the url was wrong.
I can see why someone would do this as if a site is not protected by ssh keys then the (probaly) nefarious site admin could then use the captured password to log into the fat fingered (like me) misptypers server.
But my question is: do I need to worry? (or in other words was my paranoia heart attack quickly change my ssh keys stress justified?)