1 |
On 7/17/22 11:48 PM, J. Roeleveld wrote: |
2 |
> It could, but that would open up an unsecured key to interception if |
3 |
> an intermediate host is compromised. |
4 |
|
5 |
What are you thinking? -- I've got a few ideas, but rather than |
6 |
speculating, I'll just ask. |
7 |
|
8 |
> See previous answer, the agent, as far as I know, will have the keys |
9 |
> in memory and I haven't seen evidence that it won't provide the keys |
10 |
> without authenticating the requestor. |
11 |
|
12 |
Are you concerned about a rogue requestor on the host where the agent is |
13 |
running or elsewhere? |
14 |
|
15 |
> Yes, copy/paste has no issues with multi-page texts. But manually |
16 |
> reading a long password and copying that over by typing on a keyboard |
17 |
> when the font can make the difference between "1" (ONE), "l" (small |
18 |
> letter L) and "|" (pipe- character) and similar characters make it |
19 |
> annoying to say the least. |
20 |
|
21 |
Agreed. |
22 |
|
23 |
> Currently, when that comment pops up, the first thing I do is wait |
24 |
> and wonder why it's asking for it. As all the systems are already |
25 |
> added to the list. |
26 |
|
27 |
Such a pop-up would be a very likely indication of a problem. |
28 |
|
29 |
|
30 |
|
31 |
-- |
32 |
Grant. . . . |
33 |
unix || die |