4 ms·
I've always been on the fence with technical solutions to the 'Pipe wrench' problem but one thing that I don't see mentioned that often is that there are usuall
by bolster 5y ago
I've always been on the fence with technical solutions to the 'Pipe wrench' problem but one thing that I don't see mentioned that often is that there are usually many secondary keyrings unlocked by the login password (ssh auth, saved passwords, session cookies maybe, etc);
I could see a solid usecase for a duress script that clears all these and requires 'standard' reauth, so that at least you're back to a 'defence in depth' style.
Also, in the 'Pushover' example, I can't imagine many attackers waiting to plug the thing in before starting the ~pipe wrench~ credentials discussion.