Doesn't make uploading the keys that much better. Now is the time for key rotation everywhere. Fast.
Doesn't make uploading the keys that much better. Now is the time for key rotation everywhere. Fast.
You obviously haven't worked anywhere security sensitive.
I'm not talking about whether what Grok did is bad or good, I'm talking about protecting your private key and the servers you connect to.
An unencrypted private key is no different to an unencrypted password manager, and thats a fact. Dont store secrets in plain text.
Do you think a person's private computer is a secure workplace?
If it was security sensitive space there would be no agents running amuck.
Anything that isn’t a default is optional by default. Anything that’s toggleable or configurable is optional.
Security is, always, a trade off. It is hilariously common for private keys to work as a full identifier for a person, without concern of IP or anything of the sort. Should they? Maybe, maybe not, that’s the calculus of risk management; but victim-blaming the average person who is following best practices is a bad look.
The only reasonable response from a security perspective is don't use grok, then use it sandboxed. Trying to claim it's the users fault for not using password protection and IP restrictions is completely nonsensical. Same energy as telling someone their computer is more secure when it's off.
What like a nefarious vscode extension, or npm or python library like we have seen many many times over the past 6 months.
I think you have some holes in your threat model..
PS. A simple VPN back to your static IP enables roaming.