4 ms·
I suppose in a homebrew situation, but not if age is root-installed, correct? It seems like that's a hard boundary.
by jeremyw 5y ago
I suppose in a homebrew situation, but not if age is root-installed, correct? It seems like that's a hard boundary.
- FiloSottile 5y agoI mean, most users don't root-install, but anyway the GUI application can drop a different age binary higher on the user's PATH. Or change their shell. Or a million other things. There really isn't a point to defending against code running unsandboxed on a single-user machine.
- ulrikrasmussen 5y agoI password protect my key for the sole threat model of me physically losing my device. I am aware that all other threat models that involve someone taking remote control of my device are not fully protected against, but it at least requires significantly more effort on their part versus just doing a scan for private keys on the file system.
- SEJeff 5y agoWhy not use disk encryption for this threat model?
- withinboredom 5y ago> Why not use disk encryption for this threat model? Most people don’t add a password to the disk encryption, meaning the keys can “easily” be extracted by MITM the contacts on the chip.
- jeremyw 5y agoFair enough. I believe I can mitigate enough of these to continue the utility of password-protecting my keys, but I take your point.