3 ms·
Care should always be taken when using an SSH client to connect to untrusted hosts. Make sure you’re not actually forwarding your SSH agent to the remote host,
by jclulow 2y ago
Care should always be taken when using an SSH client to connect to untrusted hosts. Make sure you’re not actually forwarding your SSH agent to the remote host, or they’ll be able to hijack your keys. Consider also that any output is processed by your terminal, and there have been a number of serious security bugs in terminal escape sequence handling in a variety of terminal emulators in the past.
- bityard 2y ago"Hijack your keys" is somewhat overstating it, all they can do with it is log into other hosts that you can log into, assuming key auth is the only factor. And only while you are connected to the original host. Terminal security bugs are not more or less serious than your average Chrome 0day.
- wkat4242 2y agoMy yubikey always requires a physical touch so even if the agent is forwarded my keys can't be used. And I'll notice when it tries because I see it flashing.
- rfdonnelly 2y agoBest to use an agent that prompts you for signing. 1Password and Yubikey do this. Are there others?