I don’t get it. Use ssh keys with a passphrase? Then stolen keys are useless?
But a far more likely scenario is that the attacker will simply leverage existing sessions/ steal a socket, which, notably, will bypass any sort of 2FA on SSH connections.
But yeah, ptrace is definitely something to watch out for. Monitoring ptrace is also something defenders can do if they're not in a position to disable it (if you're working for a software company your engineers will ptrace).
This is just snake oil that doesn't actually add protection.
There's no such thing as perfect security, but that doesn't mean you shouldn't lock your door.
Maybe I should calling the su binary directly from /usr/bin/. Any thoughts on that? Or should I open a new VT?