An update on the Fedora August 2008 intrusion
An update on the Fedora August 2008 intrusion
Posted Apr 6, 2009 8:22 UTC (Mon) by dlang (guest, #313)In reply to: An update on the Fedora August 2008 intrusion by knobunc
Parent article: An update on the Fedora August 2008 intrusion
so you end up with either setting up a key that doesn't have a passphrase, or having to store that passphrase in a script (or a bunch of scripts since they don't all run as part of a single user session)
I don't see a big win in security to counter the extra complexity here.
no, this isn't appropriate for cases like what was involved in the Fedora intrusion, but the claim was made (several posts up) that there is no legitimate reason to have a blank passphrase, and that is what I'm disputing.
