7 ms·
Don't copy your keys. Don't manage or "organize" your keys. Don't share your keys. The leaky abstractions around what you're doing with keys is a security illu
by spartas 7y ago
Don't copy your keys. Don't manage or "organize" your keys. Don't share your keys.
The leaky abstractions around what you're doing with keys is a security illusion, and you need to stop.
- kickopotomus 7y agoThis is a pretty good example of a useless comment. Telling the person to simply stop doing what they are currently doing is not a solution. Perhaps, instead, you could offer a different way to handle the situation outlined by the question.
- spartas 7y agoSorry. Generate new keys for each service, device, client, and server. Don't share them. Don't copy them.
- aeternum 7y agoThis still isn't very useful. Suppose you have a database, and an elastic number of workers that need to connect.
- nabdab 7y agoStill good advice. Generate a keypair on each new machine and only ever move around public keys. If you are copying over private keys to connect, or reusing private keys, you are doing something wrong.
- spartas 7y agoThe most common weak security point in any system is people. If you are sharing keys and you ever need to revoke a shared key, you're in for a bad time