You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在可能已被攻陷环境中生成ecdsa-sk/ed25519-sk类型SSH密钥的安全性及生成环境选择问询

在可能已被攻陷环境中生成ecdsa-sk/ed25519-sk类型SSH密钥的安全性及生成环境选择问询

Great question—this is such a critical point to unpack when working with FIDO2-backed SSH keys, since their security hinges on both the hardware itself and the environment you set them up in. Let’s break this down clearly:

First, the core security of FIDO2 SK keys

  • The biggest win with ecdsa-sk/ed25519-sk keys is that your private key never leaves the FIDO hardware. When you run ssh-keygen -t ed25519-sk (or the ECDSA equivalent), your host machine only sends a request to the security key. The key generates the private/public key pair entirely internally, then sends just the public key back to your host to save. Even if your daily environment is compromised by malware, attackers can’t siphon the private key—it never exists in your host’s memory or storage.

Potential risks in a compromised environment (even with FIDO hardware)

While the private key is safe, there are still edge cases to watch out for:

  • Tampered public key: If your host is compromised, malware could replace the public key you just generated with a malicious one. If you then upload this fake public key to servers (like GitHub or your VPS), attackers might try to use a matching key pair—but since SK keys are tied to a specific FIDO device, this would only work if they have physical access to your key. Still, it’s an unnecessary risk.
  • Spoofed authorization prompts: Some malware might try to trick you into approving a rogue key generation request. Most modern FIDO devices have physical indicators (like an LED flash or touch requirement) that make this harder, but it’s not impossible if you’re distracted or not paying close attention.
  • Compromised ssh-keygen tool: If your system’s ssh-keygen has been tampered with, it could potentially alter how it interacts with the FIDO key—though this is a more advanced attack vector.

Why a live Linux distribution is a safer choice

Using a clean, verified live Linux environment (like a bootable Ubuntu or Tails image) eliminates almost all these risks:

  • You’re working in a pristine, uncompromised environment—no hidden malware, keyloggers, or memory sniffers running in the background.
  • You can trust that the ssh-keygen tool and system libraries are unmodified, straight from the official distribution’s signed image.
  • There’s no persistent storage on the live system, so no traces of the key generation process are left behind after you reboot.

Final takeaway

If you have any reason to suspect your daily environment might be compromised, or if you’re aiming for maximum security (e.g., for accessing critical servers), using a live Linux environment is absolutely a best practice. That said, if your daily setup is well-hardened (full-disk encryption, regular updates, no untrusted software), generating SK keys directly in your daily environment is still very secure—thanks to the FIDO hardware’s private key isolation.

备注:内容来源于stack exchange,提问作者luislhl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 14:17:58