6 ms·
password protect your private keys - its what the cool kids do anyway
by WRNZ 13y ago
password protect your private keys - its what the cool kids do anyway
- drdaeman 13y agoAnd type passwords to remote host where ssh client's running. Nope, not cool at all. A possible workaround is implementing SSH agent forwarding support in Chrome app. However, you still have to trust remote ssh binary to only do what it's supposed to do while you're connected (i.e. not log your communications, not open secondary channels doing some weird stuff and so on).
- WRNZ 13y agoWhats so bad about passwords over SSL ?
- mindslight 13y agoAre you aware that passwords over SSL become even worse when the developer responds to criticism by setting up shill accounts?
- WRNZ 13y agoSorry what shill account is that ? I setup an account here today to answer any questions. Sorry for not using HN 24x7. Plus I am not a dev :)
- josephg 13y agoThe intermediate, untrusted computer (in this case koding.com's VM) can read my password.
- WRNZ 13y agoThis isn't really the intended use case, sshing from your Koding VM to other servers. However the VM we give you is yours - you have root and full control over it, if there is something on there to capture your passwords then you put it there :) (We are not the NSA)
- beambot 13y agoThat is the least convincing security statement I've heard in a long time. So what if we have root access? You can still log everything or compromise the vm under the hood -- and there really is no way to prove otherwise AFAICT (trusting trust and whatnot). In this case, the NSA would least of my concerns!
- WRNZ 13y agoI don't disagree with what your saying, however all security when there is a third party involved who can see what your doing in the clear is based on trust. We do everything we can to make sure that the only people who could possibly see what your doing is us. Should you trust us ? thats up to you. But ask yourself why we would risk everything we have built just to steal your passwords/keys ? If we did that we would be the most expensive and elaborate social engineering attack I have ever heard of :) anyway - come to the platform, do some not so serious stuff then over time maybe we can gain your trust ?
- deleted 13y ago[deleted]
- nacs 13y ago"This isn't really the intended use case, sshing from your Koding VM to other servers" Yet in your own site you say: "Stuck on a Windows machine and can’t stand using PuTTY to SSH into work? " I have to agree with OP, using this for any SSH work would be asking for trouble even if one were to use SSH keys with passwords.