3 ms·
Hmm a bit more info in the readme would be helpful. My .keychain directory only contains shell snippets that set environment variables to my SSH agent. Where's
by splitbrain 11y ago
Hmm a bit more info in the readme would be helpful. My .keychain directory only contains shell snippets that set environment variables to my SSH agent.
Where's the vulnerability? In ssh-agent? Or are we talking about a completely different keychain tool here?
- robinson-wall 11y agoI believe this is designed to operate on OSX keychain files, e.g. ~/Library/Keychains/login.keychain - and is unrelated to keychain the ssh-agent wrangler.
- splitbrain 11y agoI see. Makes sense. Thank you.
- userbinator 11y agoI think this is for Apple's .keychain files. "Where's the vulnerability?" I don't think this is a vulnerability at all. As the code at https://github.com/indutny/keychair/blob/master/bin/keychair https://github.com/indutny/keychair/blob/master/bin/keychair shows, its use seems to be just decrypting private keys with a passphrase. (Am I the only one who was surprised to see it's written in JS...?)