Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So no backups?




Correct. Private keys should never be backed up. Instead, should you need a backup, you should create a distinct key for that purpose.

That's a great plan until you're locked out of all your devices with no backup.

I think the implication is that you should own multiple client devices capable of SSHing into things, each with their own SSH keypair; and every SSH host you interact with should have multiple of your devices’ keypairs registered to it.

Right, and to never backup the keys which means losing of all your devices means you can't possibly recover.

Tuna-Fish said that instead of backing up the keys from your devices, you should create a specific backup key that is only ever used in case you lose access to all your devices.

This is indeed best practice because it allows you to alert based on key: if you receive a login on a machine with your backup key, but you haven't lost your devices, then you know your backup was compromised. If you take backups of your regular key then it would be much more difficult to notice a problem.


You can have backup private keys, they don't have to be copies of some other private keys.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: