FiloSottile/whoami.filippo.io

Add a warning for any user that has ssh-agent forwarding on by default

collinanderson opened this issue · 2 comments

You say that "ssh is designed to log into untrusted servers.", but I be a lot of githubbers have ssh-agent forwarding on by default which is not good or logging into untrusted servers.

It could be fun to have a message like "also, you have ssh-agent forwarding enabled. did you know that means I can use your private keys while you're connected?".

There is one :)

(And I just added a X11 forwarding one.)

Ahh. I suppose I should have tried it, huh? :) Thanks.