4 ms·
thimbl.net store no user data. Not even a key. Nothing.
by tricknik 16y ago
thimbl.net store no user data. Not even a key. Nothing.
- pyre 16y agoA few things: * I have to trust thimbl.net and/or you that you aren't storing anything. * Even if you released your codebase on github (or similar) there is no guarantee (to outside users) that it is the same one that you are running on your servers. * Your site is not https, meaning that my ssh password is going plain-text over the internet. * Even if your site is 100% not doing anything funny, there is the possibility for someone else to sniff the passwords flowing through your site.
- tricknik 16y agoyou can host a thimbl.net clone our your own server. There is no site yet, the system is not yet released. The login will certainly be ssl protected.
- drdaeman 16y agoWhen using publickey auth method, you don't have to provide anything (except for, obviously, username and hostname), you have to temporarily trust thimbl.net's key. I.e:, the process is: 1. thimbl.net provides its public key. 2. You add it to ~/.ssh/authorized_keys (or whatever your SSH server uses). 3. ... 4. That's it (remove key if you don't trust thimbl anymore or thimbl may even remove it by itself, at the end of setup process).
- tricknik 16y agoThat would give us access to the users account at any time. It seems requiring their password be sent with every request is more secure (over https, of course)
- pyre 16y agoThe thing that you are failing to realize is that it's easier to lock down access using a public key than a password. You can specify the amount of access an incoming ssh connection has based on the public key. You can't do that w/ a password. I could have multiple keys, all w/ different access levels, all on the same user account. There is no way to do this with a password, other than to just have separate user accounts.
- tricknik 16y agoI'm pretty clear on how ssh works. We can certainly add support keys as well, once we get the initial release out ;)