4 ms·
Which is more secure, carrying around your ssh private key on a USB or something so that you can connect to your server when you need to, or a long password, sa
by voidUpdate 1y ago
Which is more secure, carrying around your ssh private key on a USB or something so that you can connect to your server when you need to, or a long password, say a >15 character alphanumeric? and what happens if you lose your usb?
- aanthonymax 1y agoI think it's more secure to store the password on USB.
- cr125rider 1y agoSomething you are, something you have, something you know
- voidUpdate 1y agoI don't know if I can put biometric security in my ssh session
- haunter 1y agoYou can do that on Macs with Touch ID
- transpute 1y agoSome iOS/Mac SSH clients allow SSH keys to be protected by TouchID or FaceID, https://news.ycombinator.com/item?id=15853345 https://news.ycombinator.com/item?id=15853345 Might be possible on other systems with a fingerprint reader and TPM, https://news.ycombinator.com/item?id=36920105 https://news.ycombinator.com/item?id=36920105
- swores 1y agoMy yubikeys aren't biometric ones, so it's possible I'm wrong about what they support, but I'm pretty sure it's possible to have your SSH key on them and require both fingerprint and password to use it. https://www.yubico.com/products/yubikey-bio-series/ https://www.yubico.com/products/yubikey-bio-series/ (And I'm sure they're not the only company who makes such devices, they're just the one I'm familiar with myself.)
- esseph 1y agoYou absolutely can. https://linux.die.net/man/8/pam_thinkfinger https://linux.die.net/man/8/pam_thinkfinger
- cocoto 1y agoBackup the private keys, use encrypted USB keys with strong passwords and store the private keys there.
- voidUpdate 1y agobut what if someone cracks the password on my usb stick?! I'll have to store complex encryption keys for one usb on another usb
- eptcyka 1y agoUse a passphrase. Or use a yubikey, like a sibling mentioned. I wouldn’t decrypt my secret partition on untrusted devices, conversley, if I already have a trusted machine, why bother with encrypting the secrets if they can just be sniped when I mount my partition? Regular file storage for secrets is really a bad solution - use a yubikey or a secure enclave.
- mzhaase 1y agoPassphrase for the SSH key.
- jopsen 1y agoUse gpg-agent with an yubikey (a hassle to configure), or the ssh-agent from openssh with passkey on yubikey (easy to configure). Require a touch to sign, put a password on the key if your paranoid, if you really paranoid disconnect the yubikey when not in use.
- marcusb 1y agoBuy a Yubikey/Nitrokey. Get a second one and store it in a safe place in case you lose the first one.