Mosh: the mobile shell
mosh.org
mosh.org
I had the pleasure of seeing him speak at a conference last year on the topic of TCP congestion control algorithms. I admit, I expected it to be a boring presentation, but was then thrilled as it was one of the most dynamic, informative, and funny technical talks I've ever seen.
That particular presentation isn't online, but he links to several others on similar topics. I would check them out. They're probably pretty good!
EDIT: "a really dangerous feature" is accurate though. For example if all of the staff have root access on a staging machine, then anybody can steal the ssh-agent of another user on the staging machine, and use it to login as that user on production machines.
I would argue that in such an environment you really should be using LDAP+Kerberos, but if you think LDAP is too much effort (it really isn't), plain Kerberos is comparatively trivial to administer, and adding Kerberos (unlike LDAP) doesn't really require any significant changes to your environment.
I disable Kerberos ticket forwarding here, for this exact same reason. But then you don't have ticket forwarding! I don't know what I was thinking.
We use LDAP to manage public keys for each user, but they still need to supply a private key at some point.
You risk the security of your SSH key when you use -A.
Otherwise: Great tool.
Will have to check out 1.3...
Bravo.
And it doesn't require me to reconnect when I enable/disable my work VPN.
It doesn't. It uses udp, there is no connection to keep alive.
> And it doesn't require me to reconnect when I enable/disable my work VPN.
That's why this works.
What is amazing is how much it makes my day-to-day work with remote machines much more pleasant.