Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
agrinman
on May 17, 2017
|
parent
|
context
|
favorite
| on:
A Case of Stolen Source Code
Any user-level process can actually obtain your decrypted private-key:
https://blog.krypt.co/why-store-an-ssh-key-with-kryptonite-9...
clarry
on May 18, 2017
[–]
AddKeysToAgent defaults to no. Ptrace might also be disabled, depending on system. I would be more concerned about keyloggers, or any tricks that result in me running something else than the real ssh client (e.g. custom program somewhere in PATH).
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: