To show the value of known hosts files to such attackers, we present results of a study of known hosts files and other data collected from 173 hosts distributed over 25 top level domains. We also collected data on users credential management prac- tices, and discovered that 61.7% of the identity keys we encountered were stored unencrypted.