11 ms·
Show HN: Invite friends to SSH into your laptop using their GitHub handle
- matt_wulfeck 10y ago> ssh-import-I'd gh:my-gh-name That little command will pull down your GitHub public keys and add them to authorized key file for the user who runs it. Great for setting up new computers. I run it on boot-time for imbedded devices so that I can always access them.
- kingosticks 10y agoI didn't know about this, looks really useful, thanks. I wonder if there are any plans to add other protocols e.g. Keybase. Edit. Seems they are way ahead of me: https://github.com/dustinkirkland/ssh-import-id/blob/master/README.md#extending https://github.com/dustinkirkland/ssh-import-id/blob/master/...
- lucideer 10y agoThat's cool, but it seems like a lot of code to do something that: - You can do in one line of bash: curl https://github.com/user.keys https://github.com/user.keys >> ~/.ssh/authorized_keys - The bash one-liner is transparent and educational: it tells you clearly and intuitively where the keys are coming from and where they're going, educating users about the existence of the Github/Gitlab-published keys and about how the authorized_keys file works You seem to require a lot of code, and lose a lot of very real advantages, for the sake of a bit of brevity. What are the other advantages of this tool?
- koolba 10y agoExecuting the curl command with no error checking and blindly appending it to your ~/.ssh/authorized_keys could easily bork the latter. Wrapping it in a fancy command allows for error checking and response validation. Otherwise you could end up the source of https://github.com/503.html https://github.com/503.html in there!
- lucideer 10y agoPerhaps, but the simplicity of the curl command provides enough insight into exactly what it does to understand what precisely it does and what could go wrong. I can see what file it's writing to, I can check that file, I can be pretty sure it's not doing anything else weird behind the scenes.
- koolba 10y agoThat's the whole point. You have to manually do those things. It's not that you can't do them, it's that if you tell someone "Just run curl ... >> ..." without the validation part they can get hosed. Even in a script you need to be careful about it because a non-200 HTTP response still gives a zero (i.e. success) exit status.
- matt_wulfeck 10y agoAgreed! But the program manages your keys. For example, it will remove them if you remove them from GitHub.
- twakefield 10y agoHey HN - This is basically a hosted version of Teleport[0], which may scare some people. We don't store the sessions and you can always self-host if you prefer. [0] http://gravitational.com/teleport/ http://gravitational.com/teleport/
- chinathrow 10y ago> We don't store the sessions Interesting - but how can we trust you?
- jedimastert 10y agoIf you don't, just self host!
- brianwawok 10y agoWhat if I don't trust myself?
- deleted 10y ago[deleted]
- Dangeranger 10y agoThis looks pretty useful for highly dynamic infrastructure. How can nodes register with the Teleport service on provision? Do you integrate with third party authentication services like HashiCorp Vault?
- 10y ago
- problems 10y agoYeah, what a great idea, let random "cloud" services authenticate who gets to login to your machine!
- reubensutton 10y agoBeing unconstructively snarky about a concept that another member of this forum has presented is both poor manners and defies the guidelines linked in the bottom of the page
- problems 10y agoJust making a critique of the concept. Didn't think that was against any guidelines.
- blowski 10y agoI agree with your opinion, and of course critiques are always welcome here, but your comment does seem unnecessarily snarky. Perhaps something like this would be more in keeping with the HN guidelines: "It seems like a big risk to allow a little-known cloud service to authorise SSH access to your laptop. What are the use cases for this? What do you need to be careful of?"
- VeejayRampay 10y agoIf you're going to start your sentence by the heavily condescending "Yeah, what a great idea", then don't pretend you don't understand how that could be against the rules. You can't have your lunch and eat it. Especially if you're not going to provide some facts / hard evidence to back up your assertion that this is, in fact, not a good idea.
- problems 10y agoI think the rest of my statement backed that up pretty well. I'm not clear though - I'm to expect hackernews has rules which demand I weasel-word my criticisms? That seems ridiculous.
- sigjuice 10y agoI'm guessing the SSH session between me and my friend is not encrypted end-to-end because of proxies and what not in between?
- old-gregg 10y agoIt is properly encrypted: Your machine, being an SSH server, gets to decide who can login. The encryption works just with any normal SSH session: between the end user and the server (your machine). The cloud bridge running on https://teleconsole.com https://teleconsole.com simply acts as a proxy connecting sockets between two users who are behind NAT (without being able to decrypt). Disclaimer: I'm the author of Teleconsole. [edit: formatting]
- sigjuice 10y agoThanks for your reply. And apologies for my short attention span. I read "proxy", "NAT" and jumped to conclusions.
- deleted 10y ago[deleted]
- rileymat2 10y agoDoes it run as a proxy or does it just do the nat hole punching?
- old-gregg 10y agoThis page is good: http://gravitational.com/teleport/docs/architecture/ http://gravitational.com/teleport/docs/architecture/ The proxy accepts two incoming connections: from your server and from the client, then it bridges them and allows the client to negotiate an SSH handshake with the server.
- geofft 10y agoIt's very easy to get an authorized_keys file for a GitHub user account; just download (e.g.) https://github.com/geofft.keys https://github.com/geofft.keys . Presumably all this does is spawn a local SSH server with the appropriate authorized_keys file, and forward the TCP connection through the company's servers for NAT traversal. The actual connection is encrypted end-to-end.
- deleted 10y ago[deleted]
- akerro 10y agoI would rather invite 4chan to my laptop than my friends ;]
- OJFord 10y agoWould be neat if having done teleconsole -i other_users_github_id my teleconsole session ID would be sent to server along with my Github ID (optionally other user's too) so that they could teleconsole -j my_github_id to join instead of having to share session ID and fumble around with that. No more/less secure that I can see, but it would be more convenient.
- jdc0589 10y agowould be nice, but it would likely introduce some additional complexity for instances where there might be more than one live session spawned by a user.
- OJFord 10y ago> additional complexity for instances where there might be more than one live session spawned by a user I'm trying to imagine the situation that makes that worth supporting? That's not going to be a development server used by an entire team, for example, because whose Github credentials would be on it? Even so, it could just give a list of session IDs in such a case, and ask which of 1/2/3. The additional complexity is only that the lookup value is a list of strings instead of a single one, surely?
- scandox 10y agoI don't have friends that know what SSH is. Just wonderful colleagues.
- kzisme 10y agoI know the feeling...
- eof 10y agoI'm confused and have a couple questions: 1. Why would I want someone to ssh into my machine -- at least with the frequency that a service to help me do it is valuable? 2. How is this easier/better than saying 'hey bro whats your ssh pub id? -- eh.. do `cat ~/.ssh/id_rsa.pub` Over all this seems like a tool that only super technical people would ever use, and for those people adding a key to authorized keys is trivial.
- hughes 10y agoYeah, "just share the Teleconsole ID" seems like an identical step to "just share the public key".
- jdc0589 10y ago"just share the public key" doesn't solve firewall, nat, etc network issues that might be a barrier. If you went that route, you'd likely want something like ngrok too.
- bisby 10y agoThe only use case I can think of would be helping family with their linux install... and if this is already installed on their machines, it was probably put there by me... just as easy for me to put my ssh pubkeys on there too.
- cfv 10y agoWhat kind of abuse prevention measures does this have in place? As it stands it looks like a super convenient way to scp garbage into other people's computers and I'm not sure I'm sold on that.
- old-gregg 10y agoZero. It's an instant self-configuring SSH server, so the prevention measures are similar as with OpenSSH: if you don't want garbage on your computer, do not add public keys of malicious strangers into your `~/.ssh/authorized_keys` and do not open port 22 to the world! So with Teleconsole, don't invite people you don't trust. :)
- kordless 10y agoYou argument is biased and non-factual. Default ssh measures keep un-trusted entities from gaining access, normally. Conversely, once access is granted by the admin to trusted entities, the normal UNIX permissions continue to provide means by which access to the file system is limited by user permissions. Thus, simply by an admin granting access to a system, your (hypothetical) arguments become false and pointless to discuss.
- cfv 10y agoYou must be kidding me. My "argument " is a question. My "hypotetical arguments" consist of me asking if there is some thing stopping people from scp'ing things to my computer then running them. You talk like phishing and privilege escalation weren't things that exist. Have you ever managed any public-facing service of any importance?
- kordless 10y agoActually, those types of questions are called leading questions. Making a point based on a hypothetical can not be logically used to make a factual point without it being a bias, even if you phrase it as an "unknown", or question. Your last comment here shows your tendency to blame and use biases for making arguments, which is unfortunate given you appear to be asserting authority on matters of "public facing" servers. You know what they say about making assumptions. I would note that using biased arguments is an inefficient process in most cases. It's akin to recursion of a process which, in my experience, has brought many a more server to its knees than a hypothetical threat from double authorized access (hash + key).
- chrissnell 10y agoAnother way, using only software that you have already: get your friends' public keys and make a burner account on any jointly-reachable server/laptop/whatever and do a follow-the-leader screen: http://blog.endpoint.com/2009/09/gnu-screen-follow-leader.html http://blog.endpoint.com/2009/09/gnu-screen-follow-leader.ht...
- Exuma 10y agoReminds me of tmate
- mayli 10y agoSame, here. tmate.io is pretty handy in such cases.
- e_proxus 10y agoAre there any advantages to using this instead of exposing port 22 temporarily via ngrok advantages adding your friend public key to authorized_keys? (Which has the added advantage of being pure, unmodified SSH) https://ngrok.com https://ngrok.com
- jdc0589 10y agofirst thing that comes to mind is that once the session is dead, you don't have any artifacts laying around (misc authorized keys)
- vhost- 10y agoI don't like using the TCP functionality of ngrok because it seems to always use the same hostname (0.tcp.ngrok.io) with a random port. So anyone can just scan for open ports on that domain and start trying to connect to things. The HTTP forwarding at least gives you a random subdomain.
- vesche 10y agoI suppose this is useful if you have two systems both behind NAT... I've run into many situations where I'm remote and need to SSH into a NATed machine to fix something, and I typically will SSH reverse tunnel to a VPS. From the NATed machine: ssh -fN -R52222:localhost:22 user@publichost And then from the public machine: ssh user@localhost -p 52222
- mschuster91 10y agoHmm. Seems like all traffic goes through a central proxy server. Shouldn't it be possible to use the central server only for hole-punching and implement a TCP-over-UDP connection so that the clients can directly communicate with each other? (And don't the major browser vendors already have public NAT-hole-punchers for WebRTC?)
- bootload 10y ago"Hmm. Seems like all traffic goes through a central proxy server." My first thought. Also, the server and code may be secure, the weakest point is a person. cf: "You can share the Session URL with a colleague in your organization. Assuming that your colleague has access to teleport.example.com proxy, she will be able to join and help you troubleshoot the problem on "db" in her browser." ~ http://gravitational.com/teleport/docs/quickstart/ http://gravitational.com/teleport/docs/quickstart/
- aleyan 10y agoNeat. I use the following incantation when authorizing folks to ssh into my servers via github public keys: curl https://github.com/[github name].keys >> ~/.ssh/authorized_keys [github name] here should be replaced with github username of your friend or colleague. Really handy because I can just authorize them without a human request/response loop and manual key moving. Simple and no external tools needed. Normal caveats about authorizing people apply.
- OJFord 10y ago> https://github.com/[github https://github.com/[github name].keys Didn't know about that, thanks!
- schlowmo 10y agoThis was the API Ben Cox used to gather more than a million of public keys from (active) Github users to analyze their strength or weakness, which finally led GitHub to revoke the vulnerable/weak keys and notify the users.[0] Edit: Better source. [0] https://blog.benjojo.co.uk/post/auditing-github-users-keys https://blog.benjojo.co.uk/post/auditing-github-users-keys
- ezekg 10y agoComment of the year.
- cderwin 10y agoI guess it's not a surprise, but apparently gitlab does this too. kudos to both!
- a3_nm 10y agoOf course, caveats about trusting Github also apply. (If Github got hacked, the page https://github.com/[github https://github.com/[github name].keys would serve the public key of a fresh attacker-controlled key and would trigger shortly afterwards an SSH login attempt with that key towards the client IP to do evil stuff.)
- 10y ago
- rafadc 10y agoI prefer using tmux for this to be a bit more secure. I wrote a blog post about this [0] since it is a bit of a pain in the ass to set up properly. Maybe you should explore this too for your product. [0] http://joy.pm/2015/07/11/pairing_over_tmux.html http://joy.pm/2015/07/11/pairing_over_tmux.html
- patrickdavey 10y agoNice writeup, thanks for sharing.
- giblfiz 10y agohow is "curl https://www.teleconsole.com/get.sh https://www.teleconsole.com/get.sh | sh " Still considered even a remotely acceptable method for installation?
- glup 10y agothis just scares me: if they think this is acceptable, have they thought about security elsewhere?
- dividuum 10y agoUnless I misunderstood their description, they can man-in-the-middle for the disposable keys use-case anyway. If you don't trust them, don't use the software. I don't really mind having curl|sh installation instructions as long as they use https and the script is written so that truncated downloads don't cause any harm. If you know that this is a risky way of installing software, nothing prevents you from manually verifying the installation script or following the manual installation instructions. Everyone else probably doesn't have the means to properly evaluate the downloaded software anyways.
- geofft 10y agoWhat's wrong with it? If you're claiming that you don't get the ability to audit the code, I'd like to watch you audit a ./configure shell script generated by GNU autoconf. If you're claiming that you want to apt-get install so the package maintainer has audited the code, I'd like to watch them audit the ./configure shell script. Downloading and auditing code from an untrusted source is security theatre. Don't install it at all, if you don't trust it. Or use some platform (the web, iOS, Android, Qubes, etc.) that makes it such that there's no need to audit it because the app is restricted in what it can do.
- broknbottle 10y agoif the connection closes mid stream it could potentially run something catastrophic (rm -rf /) as sh will execute the partial command in its buffer.
- jeffheard 10y agoYou can use SSH keys for VNC, too. Would be neat to see a PoC that allowed you to invite someone to remote control your computer temporarily via their github handle. https://ubuntuforums.org/showthread.php?t=383053 https://ubuntuforums.org/showthread.php?t=383053
- Dangeranger 10y agoRegarding remote pair programming I haven't found a better or faster solution than TMate (https://tmate.io/ https://tmate.io/) If I am feeling paranoid about the user on the other side, I only share just the read-only link, or the web link.
- thebspatrol 10y agoThis is pretty cool. Multiplayer terminal sessions.
- bogomipz 10y agoI would be curious to hear anyones feedback on their experience running Teleport in production. I like what I have read on the site and it certainly has some nice features.
- domoritz 10y agoIf you only want to share your shell and not allow anyone to send commands, use https://shellshare.net/ https://shellshare.net/.
- pipework 10y agoThis feature was implemented in tweemux, a lighter wemux-like tool. https://github.com/PeopleAdmin/tweemux https://github.com/PeopleAdmin/tweemux It's pretty neat.
- netsharc 10y agoSo how does the -i parameter know to look in a local file or on github for the public key? Does it look for a ".pub" in the filename? Feels clunky to me.
- sleepychu 10y agoNo. I was curious about that too, they check if the parameter is a file and if it's not they try and fetch the github user's keys. [0] [0] - https://github.com/gravitational/teleconsole/blob/master/lib/identity.go#L134 https://github.com/gravitational/teleconsole/blob/master/lib...
- txutxu 10y agoPublishing the public key that you use to push to github/gitlab is not a big issue... But Re-using your github key-pair, to connect to other unknown and uncontrolled places, _is_ a security issue. Even re-using your daily system user, for this, is a security issue. But if you never did read the sshd_config man page, or never did play with its options, maybe you're unaware of this. Also the sshd could be modified at source level.
- kalmi10 10y agoCan you explain how this could be exploited (assuming that the user does not ignore warnings)?
- e12e 10y agoI'm not sure if it is a big issue without passing in -A to allow forwarding of authentication to a second server beyond the one you're logging in to. In theory you should still be in control of your secret key and the session even if the first server attempts to proxy or steal your private key. Note that your console/tty or shell might be vulnerable to a malicious server in any case. Stuff like: https://m.theregister.co.uk/2016/01/14/openssh_is_wide_open_to_key_theft_thanks_to_roaming_flaw/ https://m.theregister.co.uk/2016/01/14/openssh_is_wide_open_... seem to indicate that a patched ssh client should (no longer) leak private keys without the -A parameter...
- nodesocket 10y agoAwesome! I just launched a DevOps consulting company (https://elasticbyte.net https://elasticbyte.net), and Teleconsole looks like a great option for interactive SSH sessions with clients.
- bound008 10y agoNote to the author: Please don't have a command line flag that either means ( a valid local posix path ) or ( a username/handle from a specific online service that will be fetched over the network ). *nix cli tools are supposed to be unambiguous. I'd fork/issue/patch it, but I don't have a need to let people ssh into my any of my boxes. Just posting this here because its a valid learning opportunity that making something "easy" is not always the right choice in a cli tool, and that namespaces are important. What if I have a file named the same as a github user? Which thing will work? Will that behavior change unexpectedly? Best to make them different flags.
- e12e 10y agoI now regret that my github username isn't: ".authorized_keys".
- chilicuil 10y agoOther than using [tmate](https://tmate.io/ https://tmate.io/), I use some aliases: github-pair (https://github.com/chilicuil/shundle-plugins/blob/master/aliazator/aliases/extra/curl.aliases#L4 https://github.com/chilicuil/shundle-plugins/blob/master/ali...) github-unpair (https://github.com/chilicuil/shundle-plugins/blob/master/aliazator/aliases/extra/curl.aliases#L5 https://github.com/chilicuil/shundle-plugins/blob/master/ali...) Those add / remove keys from github to ~/.ssh/authorized_keys