[Gllug] Restricting ssh public key access

Tethys tet at accucard.com
Fri Aug 2 08:07:53 UTC 2002


>Don't forget that if your clients boxes aren't considered "safe",
>password auth is just as dangerous as public key access. i.e. if someone
>can get sufficient access to swipe their private key, they can generally
>snoop the password just as easily :/

True to an extent. However, if the clients are laptops (which they
generally are, in this case), they they're prone to theft. A stolen
laptop with a stored private key will give access to my machines,
whereas if they were forced to use password authentication, they
wouldn't get anywhere.

Tet

-- 
Gllug mailing list  -  Gllug at linux.co.uk
http://list.ftech.net/mailman/listinfo/gllug




More information about the GLLUG mailing list