Gentoo Archives: gentoo-dev

From: "Hallgrimur H. Gunnarsson" <hhg@g.o>
To: Alex Veber <coronalvr@g.o>
Cc: "Hallgrimur H. Gunnarsson" <hhg@g.o>, gentoo-dev@g.o
Subject: Re: [gentoo-dev] disabling password authentication on dev.gentoo.org
Date: Tue, 02 Dec 2003 17:00:20
Message-Id: 20031202165459.GA2970@data.is
In Reply to: Re: [gentoo-dev] disabling password authentication on dev.gentoo.org by Alex Veber
1 AB> I am not sure its a good Idea, I work on Gentoo from home and from school
2 AB> uploading and downloading files all the time, the computers at school are
3 AB> public and I can't put my key in there (If I forget to logout or
4 AB> something).
5
6 HHG> If you're going to trust a public school computer with your password in
7 HHG> the first place, you might just as well put your key there too. However,
8 HHG> should you trust a public school computer with your gentoo access at
9 HHG> all?
10
11 AB> Can you please explain whats wrong with using my password?
12
13 I never said there was something wrong with using your password.
14
15 You said that your reason for not using a key is that you don't want
16 to put the key on a public school computer. The fact that you don't
17 want to put it there suggests to me that you don't trust that particular
18 computer. Why would you trust a computer with your password but not
19 your key?
20
21 The only way your key will be compromised is if the computer itself
22 were to be compromised, and a compromised computer will give the attacker
23 your gentoo access, no matter what authentication mechanism you're using.
24
25 So my remark was, you put the same amount of trust in that computer
26 whether you're using a password or a key. Either you trust it or you
27 don't, and should you put your trust in a public school computer?
28
29 -- hhg
30
31 --
32 gentoo-dev@g.o mailing list