1 |
On Monday, 18 July 2022 08:03:44 CEST Grant Taylor wrote: |
2 |
> On 7/17/22 11:48 PM, J. Roeleveld wrote: |
3 |
> > It could, but that would open up an unsecured key to interception if |
4 |
> > an intermediate host is compromised. |
5 |
> |
6 |
> What are you thinking? -- I've got a few ideas, but rather than |
7 |
> speculating, I'll just ask. |
8 |
|
9 |
See below |
10 |
|
11 |
> > See previous answer, the agent, as far as I know, will have the keys |
12 |
> > in memory and I haven't seen evidence that it won't provide the keys |
13 |
> > without authenticating the requestor. |
14 |
> |
15 |
> Are you concerned about a rogue requestor on the host where the agent is |
16 |
> running or elsewhere? |
17 |
|
18 |
Either on the client where the agent is running, but also on the system I connected to. |
19 |
But, I just noticed the following, which is hopeful, but need to read up on this: |
20 |
https://www.openssh.com/agent-restrict.html[1] |
21 |
|
22 |
> > Yes, copy/paste has no issues with multi-page texts. But manually |
23 |
> > reading a long password and copying that over by typing on a keyboard |
24 |
> > when the font can make the difference between "1" (ONE), "l" (small |
25 |
> > letter L) and "|" (pipe- character) and similar characters make it |
26 |
> > annoying to say the least. |
27 |
> |
28 |
> Agreed. |
29 |
> |
30 |
> > Currently, when that comment pops up, the first thing I do is wait |
31 |
> > and wonder why it's asking for it. As all the systems are already |
32 |
> > added to the list. |
33 |
> |
34 |
> Such a pop-up would be a very likely indication of a problem. |
35 |
|
36 |
Agreed, which is why I always stop and think when I see that. |
37 |
Usually the answer is: "Oh, yes, I didn't access this host from my laptop yet". But that is usually |
38 |
after the 2nd or 3rd connection attempt with retyping the hostname and verifying the IP-address |
39 |
that is resolved for it first. |
40 |
|
41 |
-- |
42 |
Joost |
43 |
|
44 |
-------- |
45 |
[1] https://www.openssh.com/agent-restrict.html |