Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The parent means that an attacker has unlimited attempts at breaking the passphrase on an exfiltrated key. Once the key passphrase is broken, they can log in using the key.




Right, but my context is that devs often use no passsphrase at all. If someone can get a copy, they have instant access to whatever it has access to.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: