5 ms·
(which, if I understand correctly, won't give them the key, only the ability to use the key while the agent is running) By design, talking to to the ssh-agent
by meastham 16y ago
(which, if I understand correctly, won't give them the key, only the ability to use the key while the agent is running)
By design, talking to to the ssh-agent should not give you the decrypted key. However, in reality, anybody that could write to the ssh-agent socket could also ptrace() the agent and find the key in its memory. That would of course require becoming the user you are running ssh-agent as, but that's typically not very difficult.
What other weaknesses can you think of?
A key logger.
Basically, if you don't trust the system you decrypt your key on, all bets are off.
- lutorm 16y agoYeah, talking to the agent on the same system, I agree. But I think the risk of compromising the agent are a lot higher through the forwarded connection (which I use to log into highly populated systems). And I meant that through the connection you shouldn't be able to get the key. The key logger is a good point, but I basically only log in from my laptop, office computer or home computer. Only if one of those three are compromised, as opposed to one of the innumerable machines I log in to, should that be a risk.