3 ms·
Also it's unlikely that the extra complexity and the risks that poses is outweighed by the espoused benefits. This seems like the type of untrusted software pl
by forensic 15y ago
Also it's unlikely that the extra complexity and the risks that poses is outweighed by the espoused benefits.
This seems like the type of untrusted software plugin that results in having some horrible overlooked exploit that compromises your entire system. All so you could increase your security by some tiny margin.
- ewindisch 15y agoWhat is the danger? That some untrusted application will use the agent and mess up your servers? That is bad, I admit, but it could be worse. 'ssh -A' is much worse. The alternative? With 'ssh -A', a single compromised system will allow every user's key to be used. Not just potentially exposing all of the organization's servers, but all of the servers which all of the users may independently have access to! Those systems may also have users connecting with 'ssh -A', exposing even more systems, etc. This might not be so bad if you only access your employee's servers and you have a few machines. It is really serious if you are a contractor, or have contractors. If, say, you are a freelancer and you use 'ssh -A' to a client and the client's server is compromised, all of your other client's servers may easily become compromised. A hack as described here, preferably using a sockets-only approach, can allow your organization to essentially pre-authorize users. They must login to a host with valid credentials, receive access to an agent (but not the key), and can then authorize to other hosts.