logoalt Hacker News

collabsyesterday at 11:21 AM1 replyview on HN

How does this apply to ssh public keys?


Replies

akerl_yesterday at 1:24 PM

> Long-lived production SSH keys may be copied around, hardcoded into configuration files, and potentially forgotten about until there is an incident. If you replace long-lived SSH keys with a pattern like EC2 instance connect, SSH keys become temporary credentials that require a recent authentication and authorization check.