5 ms·
*disable ssh agent FORWARDING. Which honestly should always be disabled. There are no trusted hosts.
by bananskalhalk 2y ago
*disable ssh agent FORWARDING.
Which honestly should always be disabled. There are no trusted hosts.
- tichiian 2y agoThat's baby+bathwater. Just use ssh-add -c to have the ssh-agent confirm every use of a key.
- bananskalhalk 2y agoTIL. Thanks! Gonna do wonders when working at places where I can't use a hardware key with physical confirmation of use. My assessment still stands. Use proxyjump (-J) instead of proxy command whenever possible.
- tichiian 2y agoWhat can also help is specifying the right options right in ~/.ssh/config for certain hosts and domains: E.g. do "ForwardAgent no" globally, use a "Match *.my-trustworthy-company-domain.com" block and add "ForwardAgent yes" there. Also very good for other options that are useful but problematic when used with untrustworthy target hosts, like ForwardX11, GSSAPIAuthentication, weaker *Algorithms (e.g. for those old Cisco boxes with no updates and similar crap). Another neat trick is just using a ""Match *.my-trustworthy-company-domain.com" block" with an "IdentityFile ~/.ssh/secret-company-internal-key" directive. That key will then be used for those company-internal things, but not for any others, if you don't add it to the agent.
- yjftsjthsd-h 2y agoWhenever possible, yes, but AIUI it's not always possible; the one use case for which I believe full-on forwarding is required is using your personal credentials to transfer data between two remote servers (ex. rsync directly between servers). If there's a way to do that I would actually much appreciate somebody telling me, but I have looked and not found a way.
- deeblering4 2y ago[flagged]
- tichiian 2y agoSorry, English is not my native language. I know I sometimes sound strange because most of my use of the language is around the internet and at work, not that much casual "normal" conversation.
- bee_rider 2y agoEnglish is my native language and I have no idea what that person was talking about. Your post is fine.
- hunter2_ 2y agoI think that person was talking about having had 4 out of 5 squares in a line on their bingo card already, and stumbling across "baby+bathwater" earned them bingo. The card is metaphorical though... more of a mental buffer that just overflowed.
- bee_rider 2y agoThat makes more sense than my solution. As far as I’m concerned the baby and the bath water is just a normal expression. I thought it was something about the use of “confirm,” haha.
- hoistbypetard 2y agoMine too, and I think the post is fine also, but I have some idea of what that person was talking about. For a while, in some corporate environments, it was a recurring phenomenon to hear someone dismiss an urge to be cautious by saying "You're throwing out the baby with the bathwater." So I can see where someone might count it toward buzzword bingo. But this post also offered an alternate solution when saying "baby+bathwater", so the bingo caller should refuse to score this one.
- 2y ago
- lrvick 2y agoOr use a hardware backed ssh key you have to tap once for every use, like a Yubikey or Nitrokey.
- derefr 2y ago> There are no trusted hosts. ...your own (headless) server that's in the same room as you, when you're using your laptop as a thin-client for it?
- xandrius 2y agoWith all these recent exploits, I wouldn't even be 100% sure of that.
- wolletd 2y agoBut if I can't trust even that host, I also can't trust the host I'm working on and which doesn't need agent forwarding to access my SSH agent.
- hot_gril 2y agoTrusting one host is safer than trusting two hosts.
- jethro_tell 2y agoThis is where certs are nice, sign one every morning with a 8/12 hour TTL
- quibuss 2y agoInteresting idea. Does need some automation though to make it practical irl.
- dotancohen 2y agoDepending on what it's serving, and how up to date it is, and who else is on that network and can access the server, and who else can come into that same room when you're not there, and from where you get the software that you install on that server... it might be less trustworthy than you think.
- 2y ago
- sva_ 2y agoI've found myself to be much more comfortable to just define all my private keys in ~/.ssh/config on a host-by-host basis.
- jmole 2y agoAFAIK, this doesn't solve the SSH agent problem - the problem is the agent has access to all of those keys regardless of the host you connect to. So forwarding your SSH agent means an administrator of the system you're connected to could use any of those host keys loaded in the agent to connect to their associated machine.
- deleted 2y ago[deleted]
- contingencies 2y agoDefault for the last 24 years according to https://github.com/openssh/openssh-portable/blame/385ecb31e147dfea59c1c488a1d2011d3867e60e/ssh_config#L21 https://github.com/openssh/openssh-portable/blame/385ecb31e1...