|
|
|
|
|
by ecesena
3754 days ago
|
|
I think the most important thing is key rotation, and generally I do it every year or so. I prefer a single ssh key for almost everything. It's on only 1 laptop that I use daily. There is no protection on the key itself, but I always lock the laptop screen (password protected) when I leave the laptop alone. I have other laptops/devices, usually with different keys. My "master" key is also on my 2nd laptop. Although I could have a passphrase there, I still prefer no protection except screen locking. This said, this 2nd laptop never leaves my home, where only trusted (and "innocuous") people can touch it. |
|
Of course, in every security scenario the risks determine the level of security, but having a passphrase has no practical downsides.