3 ms·
> Public keys really are the better way to handle user auth, less of a minefield for regular users. I'll go along with that, thou i consider a secret that resi
by samoa42 6y ago
> Public keys really are the better way to handle user auth, less of a minefield for regular users.
I'll go along with that, thou i consider a secret that resides in my brain vastly more secure than one residing on my disk.
- sliken 6y agoI 100% agree. But with ssh (ideally) the passphrase never leaves the computer you are physically touching. With passwords you are sending it to remote computers where it could be compromised. Thus the standard practice of forcing all users to change their passwords when a server is compromised.
- koheripbal 6y agoI've come to realize that if I don't use a password at least once per month, I will forget it. ...so, this isn't great advice either. Password vaults are important..... at which point, you can just use a complex unique password.
- yjftsjthsd-h 6y agoOkay, so use the 56 bits that you can store in your head as a passphrase to control the 256 bits (for ed25519) on your disk.