Stealing unencrypted SSH-agent keys from memory (2014)
blog.netspi.com
blog.netspi.com
Those concerned about this attack vector should use hardware tokens, like a YubiKey. They aren't infallible, as they could be stolen while unlocked with some USB trickery to keep them active, but it beats being able to trivially dump the key material.
Further on this line of thinking, it’s an entirely reasonable extension of the “secure bastion” on modern processors to allow for a temporary private key store - You load your private key into the bastion and get back a key handle, which can then be used to do TLS handshakes but only through the bastion. Once that’s done, recovery of the private key is impossible, only abuse of it by the kernel (by passing that handle to other processes)
https://www.kernel.org/doc/html/latest/networking/tls-offloa...