ssh and security
Posted Dec 5, 2003 18:24 UTC (Fri) by
giraffedata (subscriber, #1954)
Parent article:
ssh and security
OK, but lets cut to the chase on what change the letter proposes: It does not propose a challenge-response system, because SSH already has that. It proposes to move authentication out to an isolated, hardened system.
The paper with the passwords on it is such a system. It can't do a fraction of what a Linux system can do, and so is much harder to compromise. The smartcard has similar properties. Because it doesn't have the flexibility to do things like run a web server, it's much harder for someone to break into it and steal your keys than it is to break into a Linux system and steal its SSH keys.
(
Log in to post comments)