Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you please elaborate on why preventing ssh agent is good?


Forwarding your agent exposes your authentication secrets to the machines you're connecting to.


A bit late, but I feel it's important to clarify it exposes something like "authentication capability" not the actual secrets. It's temporally bounded.


Yeah, I had the same itchy thought when I wrote this; I decided to keep it simple.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: