On 7/17/22 11:48 PM, J. Roeleveld wrote:
It could, but that would open up an unsecured key to interception if an intermediate host is compromised.
What are you thinking? -- I've got a few ideas, but rather than speculating, I'll just ask.
See previous answer, the agent, as far as I know, will have the keys in memory and I haven't seen evidence that it won't provide the keys without authenticating the requestor.
Are you concerned about a rogue requestor on the host where the agent is running or elsewhere?
Yes, copy/paste has no issues with multi-page texts. But manually reading a long password and copying that over by typing on a keyboard when the font can make the difference between "1" (ONE), "l" (small letter L) and "|" (pipe- character) and similar characters make it annoying to say the least.
Agreed.
Currently, when that comment pops up, the first thing I do is wait and wonder why it's asking for it. As all the systems are already added to the list.
Such a pop-up would be a very likely indication of a problem. -- Grant. . . . unix || die