4 ms·
Any halfway decent tech team manager or sysadmin should make a very clear company-wide policy against passphraseless SSH keys for developers. Github compares i
by yetanotherjosh 16y ago
Any halfway decent tech team manager or sysadmin should make a very clear company-wide policy against passphraseless SSH keys for developers.
Github compares it to leaving your password in a file on your computer for attackers to find, but it's MUCH worse than that. Such a password file could be anywhere on your computer and an attacker would have to search for it and may never actually find it unless it was clearly labelled.
SSH keys are defined in your SSH config file and attackers know exactly where that lives. Using a passphraseless ssh key is more like leaving your password on a sticky note attached to your monitor.
This article is spreading bad advice here to users who don't understand why, and the author should update his post and retract it.
- hollerith 16y agoHelp me out here: if an attacker can get into my account on my OS X or Linux box, he can run sudo, which means he can replace my ssh client with one that will capture my passphrase the next time I use it. Can you give a concrete example of a scenario in which an attacker will be able to read my SSH config file but not be able to get into my account? Suppose the SSH config file is not backed up. I am not saying you are wrong about the need for a passphrase, BTW.
- rmc 16y agoOn Linux you need to enter your password to run sudo. If someone can read all the files in your home directory but not make you enter sudo, then they can see your ssh keys but be unable to replace /usr/bin/ssh
- hollerith 16y agoThanks. I have been using OS X where sudo does not ask admin accounts for a password.