Jump to content

Are passwords in ssh keys really necessary?

Ticua

They really seam to be just another hassle that won't add that much of security as it will probably be bruteforced anyways. Just asking this because I recently got ssh-bruteforced because I was lazy and set up ssh with password.

 

English is not my main language, point any mistakes if made Thanks

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, Ticua said:

They really seam to be just another hassle that won't add that much of security as it will probably be bruteforced anyways. Just asking this because I recently got ssh-bruteforced because I was lazy and set up ssh with password.

 

English is not my main language, point any mistakes if made Thanks

As I understand it its just an extra layer so that if your key somehow got leaked, they still would have to brute force to use it.

So no, its not actually necessary so long as your key is not compromised, or if it was you notice quick enough to revoke it from the server.

Router:  Intel N100 (pfSense) WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz)
WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz) Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~800Mbit down, 115Mbit up)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
Share on other sites

Link to post
Share on other sites

An SSH key with a password is always more secure than an SSH key without a password. It's just an added layer of defense so that if an attacker gets your SSH key, they still need to crack the password as well. A strong password on an SSH key means that even if someone gets your key the server is still secure, although obviously that key should still be revoked.

¯\_(ツ)_/¯

 

 

Desktop:

Intel Core i7-11700K | Noctua NH-D15S chromax.black | ASUS ROG Strix Z590-E Gaming WiFi  | 32 GB G.SKILL TridentZ 3200 MHz | ASUS TUF Gaming RTX 3080 | 1TB Samsung 980 Pro M.2 PCIe 4.0 SSD | 2TB WD Blue M.2 SATA SSD | Seasonic Focus GX-850 Fractal Design Meshify C Windows 10 Pro

 

Laptop:

HP Omen 15 | AMD Ryzen 7 5800H | 16 GB 3200 MHz | Nvidia RTX 3060 | 1 TB WD Black PCIe 3.0 SSD | 512 GB Micron PCIe 3.0 SSD | Windows 11

Link to comment
Share on other sites

Link to post
Share on other sites

Depending on your use-case its most probably secure enough with just the keys. Key based auth is more secure than password auth anyway.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×