On 7/17/22 11:48 PM, J. Roeleveld wrote:
It could, but that would open up an unsecured key to interception if an intermediate host is compromised.

What are you thinking? -- I've got a few ideas, but rather than speculating, I'll just ask.

See previous answer, the agent, as far as I know, will have the keys in memory and I haven't seen evidence that it won't provide the keys without authenticating the requestor.

Are you concerned about a rogue requestor on the host where the agent is running or elsewhere?

Yes, copy/paste has no issues with multi-page texts. But manually reading a long password and copying that over by typing on a keyboard when the font can make the difference between "1" (ONE), "l" (small letter L) and "|" (pipe- character) and similar characters make it annoying to say the least.

Agreed.

Currently, when that comment pops up, the first thing I do is wait and wonder why it's asking for it. As all the systems are already added to the list.

Such a pop-up would be a very likely indication of a problem.



--
Grant. . . .
unix || die

Reply via email to