4 ms·
Is ssh-agent even worth the trouble?
by throwdecro 5y ago
Is ssh-agent even worth the trouble?
- johnklos 5y agoYes.
- inetknght 5y agoNo. I have not found a single use case where an ssh-agent is worth the security problems it adds.
- dataflow 5y agoHow do you push/pull a private GitHub repo on a remote machine you're SSHed into?
- janci 5y agoDeploy keys
- dataflow 5y agoSo you leave a copy of a key that can push to your repo on the machine? How in the world is that supposed to be more secure than forwarding an agent that only authenticates you when you're actually connected? At least you don't leave a copy of the key itself on another machine.
- janci 5y agoSorry, did not notice the push part. But it solves the pull part nicely.
- dataflow 5y agoEven for pulling I fail to see why having the deploy key sitting on the machine is supposed to be more secure than having it in your agent.
- janci 5y agoYou have a key on a single machine that can only read a single repository with no additional hassle about securing the agent to not give out all your secrets at once, while it does not add any additional risk, as the remote machine already has full copy of the repo, so there is almost nothing to gain with the key if attacker had compromised the machine already.
- dataflow 5y agoIf someone lifts the key they get perpetual access to your entire repo without any further need to have access to your machine. If they lift the repo then they get a snapshot of the branch(es) you have have in it at that moment in time - they'll need continued access to the machine if they want continued access to the data. There can be a nontrivial difference here right?
- inetknght 5y agoBeing SSH'd into a machine doesn't matter. You can create a new key _on that machine_ and authorize _that key_ for the specific purpose you need. Or you can also just clone the repo on your local machine and add the remote machine as a git repo remote. Then you proxy all commits between github and the remote machine. If you don't want to proxy commits between three repos (github, your local, your remote) then you could install sshfs on your local machine and sshfs-mount your remote machine. Regardless; if you're running git on the remote machine then the root user of that remote machine would have access to the key. Why let them have access to _your_ key when they're only administering a machine for that repository? Let them have access to a shared key.
- teitoklien 5y agoUse repo specific github oauth tokens with the least amount of permissions as possible