Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any user-level process can actually obtain your decrypted private-key: https://blog.krypt.co/why-store-an-ssh-key-with-kryptonite-9...


AddKeysToAgent defaults to no. Ptrace might also be disabled, depending on system. I would be more concerned about keyloggers, or any tricks that result in me running something else than the real ssh client (e.g. custom program somewhere in PATH).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: