But how do you secure that against the threat of a keylogger running on a developer's Linux machine? Am I overthinking here? Is it already game over if the attacker runs software on that developer's machine?
But how do you secure that against the threat of a keylogger running on a developer's Linux machine? Am I overthinking here? Is it already game over if the attacker runs software on that developer's machine?
https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht...
Yubikeys, and some others, also implement Ed25519 and discoverable key storage, so you can store SSH keys on the Yubikey itself.
From "man ssh-add" on a Mac:
-K Load resident keys from a FIDO authenticator.
No third party tools are needed.You can store an SSH key on the security key itself, and you can use it on any machine you want without needing a corresponding key handle file. Downside to this is that anyone who has your security key potentially has your SSH key.
If you use non-discoverable keys, you need a corresponding key handle to use SSH with your security key. That key handle can be treated like any SSH key, in that you can password protect it and use many rounds of PBKDF2 to secure it. Without that handle you can't use the security key for SSH.
The first method requires you to enter your FIDO password any time you need access to the key, along with touching the authenticator. Using the second method, you can use a keyring to store your key handle's password and/or use an SSH agent, and you potentially just need to unlock it once with a password, then you only need to confirm via touch when you want to use the key.