3 ms·
I confess, I hadn't thought of that threat. It's an interesting thing to think about. My initial reaction is this: Couldn't malware on my laptop also monitor m
by mapgrep 15y ago
I confess, I hadn't thought of that threat. It's an interesting thing to think about.
My initial reaction is this: Couldn't malware on my laptop also monitor my keystrokes when I unlock the key? Or when I log in to my VPS web interface? I mean, if the goal is to have a malware infested computer that is no threat to external systems, it seems like there are tons of other files/apps/system you'd also want to password protect, to the point of making the computer almost impossible to use.
Still, it's an interesting point. SSH keys are more sensitive. I do keep an extra password on my password manager.
- blibble 15y agoaye, it's pretty easy to ptrace() ssh-agent and extract the key directly from memory. once malicious third party code has executed on your machine as you it's game over.