2 ms·
SSH secret key file exfiltration by running "npm install" or the like is a concern, and by using YubiKeys this type of attack is eliminated. You can also enfo
by Androider 5y ago
SSH secret key file exfiltration by running "npm install" or the like is a concern, and by using YubiKeys this type of attack is eliminated.
You can also enforce usage of YubiKeys, but you can't really enforce every developer sets a passphrase on their locally generated SSH key file.
And it's a convenient, and consistent way of authentication: Your work Google Workspace account uses and enforces a YubiKey, your AWS account login uses and enforces a YubiKey, and now your GitHub account also uses (but cannot not yet be made to enforce AFAIK) a YubiKey. It's less hassle than using one-time codes with fifty-seven different apps and cloud environments, so there's not much user push back.