3 ms·
Duh. Where exactly did you get the idea that your private key would be lost? It's no longer private because the attacker can use your forwarded connection "to a
by jsn 16y ago
Duh. Where exactly did you get the idea that your private key would be lost? It's no longer private because the attacker can use your forwarded connection "to authenticate using the identities loaded into the agent". It's right there in ssh man page.
Neither did I ever suggest using the second agent on the middle computer -- sure, it's obviously stupid.
> It's specifically built to prevent what you described as the danger.
You're wrong. See "man ssh", it's documented right there in "-A" option description.
- Groxx 16y agoBecause you mentioned: >your private key is not private anymore and: >the attacker who gets your key gets instant access to all other machines you access with that key. Which is wrong. They don't get your key. They get the ability to authenticate as you while you are connected, and nothing else.