4 ms·
Good find! I was always curious how this worked. I'm a big fan of tools like secretive[1] that can help solve this problem by using biometrics to shift the UX/
by g1a55er 3y ago
Good find! I was always curious how this worked.
I'm a big fan of tools like secretive[1] that can help solve this problem by using biometrics to shift the UX/security trade-off and thus make it feasible to always require some kind of authentication to sign a token with a key.
I'm not aware of any tools that do the same for Linux, and a quick Google search doesn't turn up much[2]. It does look like you can at least get a notification[3], though.
This could provide another layer of protection on the user's endpoint device in addition the network monitoring called out in the article. Defense in depth, and all that.
[1] https://github.com/maxgoedjen/secretive https://github.com/maxgoedjen/secretive
[2] https://unix.stackexchange.com/questions/705144/unlock-an-ssh-private-key-with-a-biometric-token-instead-of-a-passphrase https://unix.stackexchange.com/questions/705144/unlock-an-ss...
[3] https://www.insecure.ws/2013/09/25/ssh-agent-notification.html https://www.insecure.ws/2013/09/25/ssh-agent-notification.ht...
- rakkhi 3y agoJust don't use SSH keys at all. Anywhere. https://substack.com/@rakkhi/note/c-40163543?r=1afqp https://substack.com/@rakkhi/note/c-40163543?r=1afqp
- johnklos 3y agoThat's shortsighted. Why not go all the way and just stop using computers altogether?
- lxgr 3y agoHuh? So what should we use to e.g. SSH to a server to debug a crashed or hanging process, login to a dev instance etc.? SSH keys are also not “just long passwords” at all.
- cortesoft 3y agoNot using SSH to configure a machine is smart, but saying no SSH at all is not feasible for many things. When something goes wrong, you need to be able to connect to a running machine and poke around, and you don’t know how you will need to poke until you are doing it.
- gruturo 3y agoThe statement "SSH keys are just long passwords" in your linked post is a huge red flag that you don't understand enough about how they work and are in no position to dispense advice (that anyone sane should heed) on the subject. To start (but it would be a longer discussion), passwords can be captured as you type them into a compromised host, SSH keys can't. Also SSH keys can reside on a security device (TPM, smartcard, HSM, security token, whatever) and this way they can _never_ be captured, barring exploits on those hardware devices, even if your workstation is compromised. Some hardware security devices have features like touch-to-authorize, or even biometrics, for every single usage. SSH keys can be _used_ while unlocked, but not from a compromised remote site (unless you do agent forwarding, which this article is all about), and never captured from there. Passwords have literally _none_ of the above features. Forwarding usually bad. SSH Keys otherwise good. Passwords so bad they're not worth comparing to anything. (and yeah, there's stuff even better than SSH keys)
- deleted 3y ago[deleted]
- lxgr 3y agoAgent confirmations don’t need local authentication really; local confirmation is what’s important here.