4 ms·
I use a distinct key for each remote account. Although it's meant to be infeasible to infer a private key from a public key, distinct keys give me another layer
by gradschool 1mo ago
I use a distinct key for each remote account. Although it's meant to
be infeasible to infer a private key from a public key, distinct keys
give me another layer of defence in depth in case an attacker ever
finds a way to do it. Another advantage is that I can use passphrases
selectively. For example, if I have an unpriviledged remote account
with shell access disabled because it's used only for proxy tunnelling,
it's less important to have a passphrase protecting its key than it
would be for a remote root account, and not having one could be more
convenient.