top | item 29600332

(no title)

jeremyw | 4 years ago

I suppose in a homebrew situation, but not if age is root-installed, correct? It seems like that's a hard boundary.

discuss

order

FiloSottile|4 years ago

I mean, most users don't root-install, but anyway the GUI application can drop a different age binary higher on the user's PATH. Or change their shell. Or a million other things.

There really isn't a point to defending against code running unsandboxed on a single-user machine.

ulrikrasmussen|4 years ago

I password protect my key for the sole threat model of me physically losing my device. I am aware that all other threat models that involve someone taking remote control of my device are not fully protected against, but it at least requires significantly more effort on their part versus just doing a scan for private keys on the file system.

jeremyw|4 years ago

Fair enough. I believe I can mitigate enough of these to continue the utility of password-protecting my keys, but I take your point.