4 ms·
Careful when SSHing into an untrusted host. They can find your public key(s) that way and maybe identify who you are on GitHub.
by 0942v8653 11y ago
Careful when SSHing into an untrusted host. They can find your public key(s) that way and maybe identify who you are on GitHub.
- pmoriarty 11y agoWhat are some good ways to protect against that? My first thought is to create an entry in my ~/.ssh/config with an entry for the untrusted host I'm going to ssh in to, using the "IdentityFile" keyword to point to some bogus/misleading identity file. How does that sound?
- placeybordeaux 11y agoA simple solution would be to create a dummy account and use that for sshing into untrusted hosts.
- voltagex_ 11y agoI wonder if you can turn off automatic use of public keys for "*", and then enable it in .ssh/config on an as-needed basis.
- andreabedini 11y agoTotally possible, I do this. Also I have a different key per host (using %h in IdentityFile)
- vinceguidry 11y agoDo you use pass-phrases with your per-host keys? I wanted to do this, but was unable to make it manageable. ssh-agent will only try so many keys before moving on.
- andreabedini 11y agoNo, I don't use key pass-phrases.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- alexbecker 11y agoJust use a different key for github than for everything else. You can specify this in your ssh config using the IdentityFile directive.
- marklgr 11y agoIn your .ssh/config file: Host * # Do not send pubkey to each and any host PubkeyAuthentication no # Use Agent IdentitiesOnly yes Then override 'PubkeyAuthentication' to yes for each known server you want to connect to.
- cyphar 11y agoI don't understand, why is that a bad thing? Maybe it might be an issue if you're trying to do something anonymously (but at that point, you shouldn't be using your regular machine anyway).
- windowsworkstoo 11y agoIt's not, it's a "public" key.
- Drdrdrq 11y agoIt's not a problem from security perspective. It is a problem from privacy perspective.
- illumen 11y agoPrivacy is security.
- illumen 11y ago"Security is the degree of resistance to, or protection from, harm." "Privacy: a secret matter." "Privacy: freedom from unauthorized intrusion." "Privacy: the quality or state of being apart from company or observation." So you see, privacy IS security.
- Drdrdrq 11y agoI can't tell if you forgot /s?
- craigching 11y ago> It's not, it's a "public" key Not just any public key, it's your public key. It identifies you.
- mikeash 11y agoIt's rather unexpected. Browsers carry so much baggage that you need a private mode, I wouldn't have expected something like ssh to have this sort of problem before I read about how it exposes your keys.
- txutxu 11y agoI could be more worried about a modified sshd, that triggers different code paths in the client than the expected ones.
- dspillett 11y agoIf your identity is that sensitive keep a standard public key that is used by default, but for services where you might want your identity to not be linked to other accounts/places/activities have a separate key for each and specified where to use it in you SSH config (or by naming with the -i parameter on each ssh call).
- marssaxman 11y agoWhy would that be a problem?