3 ms·
I like keys with passphrases, although their security is somewhat questionable as you say. At least it prevents the scenario where the key is accidentally expos
by STRML 12y ago
I like keys with passphrases, although their security is somewhat questionable as you say. At least it prevents the scenario where the key is accidentally exposes somewhere via a lost storage device / bad scp command / whatever. And sometimes, for one-off non-prod servers, I don't bother with setting up AuthenticationMethods to require a separate password.
I think key + pass + OTP is the best of all worlds, except convenience. But in my opinion, it should be a pain to get into your servers, especially if they hold sensitive data. I am especially a big fan of hardware tokens like yubikeys; the best part is, you know when you lose them and can rotate keys. Even with Google Authenticator, you are not quite sure if the keys can be lifted from your phone.