Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's why you should use ssh-agent and protect your private key with a passphrase.


It's useful, but if an attacker got a shell on the dev laptop, I assume he could just coredump the ssh-agent process and steal the unlocked key from there.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: