3 ms·
Any time you access an SSH connection from a different computer, you basically need the password.
by timw4mail 2y ago
Any time you access an SSH connection from a different computer, you basically need the password.
- LtWorf 2y agoIf it's in the cloud, you pass the public key when creating the vm. If it's a real machine, ask the data center person to do it.
- krisoft 2y agoThis is not true. SSH keys are a viable alternative.
- sseagull 2y agoIf I can be charitable, I think they mean a different computer than one you usually use (that doesn’t have the SSH key already in authorized_keys). Spouses computer, etc.
- traceroute66 2y ago> If I can be charitable, I think they mean a different computer than one you usually use If I can be charitable .... What the hell are you doing storing your SSH keys on-disk anyway ? :) Put your keys on a Yubikey, take your keys with you.
- unethical_ban 2y agoRight, much easier than a password! And so easy to backup! I'm not arguing it isn't more secure. The point of this subthread is that SSH keys are not as easy to do ad-hoc as passwords, especially when moving workstations.
- nottorp 2y ago> Right, much easier than a password! And so easy to backup! Extremely easy to recover from when the device you rely on to authenticate for everything gets lost or stolen too!
- unethical_ban 2y agoExactly. If I can't use TOTP with backup codes, I'm not using MFA.
- doublepg23 2y agoDoes that work with macOS? I’m currently using 1Password as my ssh key agent.
- koito17 2y agoIt indeed works on Mac OS. I have been using SoloKeys with ed25519-sk keys for about three years now. It should be sufficient to run ssh-keygen -t ed25519-sk while a FIDO2 key is connected. You may need to touch the key to confirm user presence. (At least SoloKeys do). If I recall correctly, the SSH binaries provided by Apple don't have built-in support for signing keys, but if you install OpenSSH from Nix, MacPorts, etc., then you don't have to worry about this. Another thing to be mindful of is that some programs have a very low timeout for waiting on SSH authentication, particularly git. SSH itself will wait quite a long time for user presence when using a signing key, whereas Git requires me to confirm presence within about 5 seconds or else operations fail with a timeout.
- nerdbert 2y agoWhy would you ever do that? How do you know it is not compromised? Carry your phone (many people already do this on a daily or near-daily basis in 2024) and use that in an emergency.
- Rucadi 2y agoIt's just an usually bigger password.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]