3 ms·
I think the "untrusted system" in question is the system you're logging on from, because that's the only place where the private key could be compromised. I gue
by voyou 11y ago
I think the "untrusted system" in question is the system you're logging on from, because that's the only place where the private key could be compromised. I guess the idea is something like, you have a desperate need to log in to a server but the only computer you have physical access to is a machine you don't control (in an internet cafe, say). So you keep your one-time SSH key on a flash drive, use that key on the untrusted machine to log into your server, and you don't have to worry about the untrusted machine keeping a copy of your key (because that key is no longer valid). On the other hand, you do still have to worry about the untrusted machine injecting malicious commands into your session (including, possibly, malicious commands which would allow the attacker to log in to the server as you again in the future).