5 ms·
That’s why ideally you use a pass phrase with you ssh key. Apps can still read it but not use it.
by Bootvis 4y ago
That’s why ideally you use a pass phrase with you ssh key. Apps can still read it but not use it.
- progbits 4y agoEven better, if possible switch to something like PGP keys on Yubikey which prevents exfiltration of the private key, and will only sign things when you enter PIN / touch the device.
- doubled112 4y agoThis has been my SSH key solution for a while now. Worked smoothly on most systems. Kind of messy on Windows, because there are so many SSH agent implementations, but GPG4Win's latest version works with the native SSH now. Real progress.
- tkanarsky 4y agoI find that the PIV smart card stack is needlessly complicated if all you're trying to do is add a resident SSH key to your yubikey. Look at `ed25519-sk` [0], which is supported by default by recent versions of OpenSSH (and dropbear? idk) [0]: https://news.ycombinator.com/item?id=29231396 https://news.ycombinator.com/item?id=29231396
- doubled112 4y agoPGP is definitely complicated if you’re not going to use it for other functionality. And that’s completely separate to the PIV functionality on the key.
- tkanarsky 4y agoOh, I was under the impression that PIV referred to the smart card protocol and PGP was an application making use of that protocol, something like TCP and HTTP. Looks like I'm mistaken, thanks!
- egberts1 4y agoNot the map you are looking for but there is this comparison chart of SSH clients and its algorithms. https://ssh-comparison.quendi.de/comparison/cipher.html https://ssh-comparison.quendi.de/comparison/cipher.html
- doubled112 4y agohttps://github.com/rupor-github/win-gpg-agent/blob/main/docs/pic1.png https://github.com/rupor-github/win-gpg-agent/blob/main/docs... Don’t forget this diagram of all the agents, protocols and bridges you might hit on Windows.
- egberts1 4y agoThat is the scariest system diagram chart that I have ever seen. It should be a prime example of what NOT to do.
- grishka 4y agoBut then enter it every time you need to use the key, thus negating the advantage of just magically logging in without passwords? Because if you use ssh-add and only enter the passphrase once per reboot, apps will be able to use it, that's the point.
- Xylakant 4y agoYou can (and should) use ssh-agent/ssh-add to handle the key for you. It will still protect you against apps reading the key - ssh-agent only performs crypto operations on behalf of programs and will not hand out the private key.
- jesprenj 4y agoThe app in question can just dump the memory of ssh-agent and obtain the private key from there. Or not?
- tristor 4y agoUsually no. It requires root / Admin to dump memory of other processes, generally. Although vulnerabilities do exist.
- jesprenj 4y agoAre you sure this is how, let's say, Linux behaves? I tested it now in a minimal privilege account in a chroot on Debian 11 that I use for login from untrusted machines, and strace worked. This is how I captured a password entered into a ssh client password prompt, opened in another login shell of the same user: -bash-5.1$ ps aux | grep abcde z 2502130 0.0 0.3 9500 6132 ? S+ 18:04 0:00 ssh abcde@localhost z 2502140 0.0 0.1 6316 2336 ? S+ 18:04 0:00 grep abcde -bash-5.1$ strace -p 2502130 strace: Process 2502130 attached read(4, "s", 1) = 1 read(4, "e", 1) = 1 read(4, "c", 1) = 1 read(4, "r", 1) = 1 read(4, "e", 1) = 1 read(4, "t", 1) = 1 read(4, "\n", 1) = 1 write(4, "\n", 1) = 1 ioctl(4, TCGETS, {B38400 opost isig icanon -echo ...}) = 0