This is fascinating. The Best Western I'm staying in MITMs SSH sessions (even on non-standard ports). If you accept their host key and still attempt to connect to a normal (i.e., password-forbdden) server, the middlebox sends back an SSH protocol error message of

> Connection blocked because server only allows public key authentication. Please contact your network administrator.

I've *never* seen public WiFi MITM SSH before.

Amusingly, they still allow wireguard traffic through unmolested.

@roguelazer that is interesting. Be fun to nmap the mitm server....

