3 ms·
>> apple thinks ... they can store it safely. I can understand why people who care about this would be a little miffed. Most devs I know - including me - don't
by developer2 10y ago
>> apple thinks ... they can store it safely.
I can understand why people who care about this would be a little miffed. Most devs I know - including me - don't put passphrases on their private ssh keys. People who do put passphrases on their keys are going to fall into two camps:
1. They do it out of habit or because they were told it's important, but they don't really care. This issue will not be important to them whatsoever.
2. They do it because they have explicitly chosen to ramp up their security, or are legally required to do so to conform to strict regulations. These people will be absolutely outraged that Apple has made this the default. Any local script or app can now ssh to a remote server and run commands, using a private key that requires a passphrase, without prompting for that passphrase or having explicitly added it to an ssh agent?
I personally don't give a damn. But holy fuck, Apple over-extended on this one. There are some IT employees out there who won't be getting any sleep over the next couple of days while they secure against this issue (and revoke/reissue all their ssh keys).
- smw 10y agoWhy wouldn't you put a passphrase on your key?! An agent, and especially keychain support, removes almost all the inconvenience, and it adds a tremendous amount of security.
- zaroth 10y agoAlthough this depends very much on the particular form of key you are using. Password encrypted SSH keys were getting a single round of MD5 for the longest time. This was fixed initially only for Ed25519 keys, to use bcrypt(5), which is still not fantastic, but a hell of a lot better than md5(1). Newer OpenSSH (v6.5 and later) has a new file format and allows specifying an arbitrary bcrypt complexity regardless of the key type. Look for your private key file to start with; -----BEGIN OPENSSH PRIVATE KEY----- [1] - https://pthree.org/2014/12/08/super-size-the-strength-of-your-openssh-private-keys/ https://pthree.org/2014/12/08/super-size-the-strength-of-you...