<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Institute of Ineptitude</title><link>https://ineptitude.ca/tags/security/</link><description>Recent content in Security on Institute of Ineptitude</description><generator>Hugo -- 0.153.1</generator><language>en</language><lastBuildDate>Wed, 03 Dec 2025 16:48:43 -0700</lastBuildDate><atom:link href="https://ineptitude.ca/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>1Password ssh agent config...</title><link>https://ineptitude.ca/writing/1password-agent-config/</link><pubDate>Wed, 03 Dec 2025 16:48:43 -0700</pubDate><guid>https://ineptitude.ca/writing/1password-agent-config/</guid><description>&lt;p&gt;If you&amp;rsquo;re doing SSH keys right&amp;hellip; they tend to &lt;em&gt;accumulate&amp;hellip;&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Keys unique to various environments or even specific hosts&lt;/li&gt;
&lt;li&gt;Rotation (new keys generated, old keys deprecated and phased out)&lt;/li&gt;
&lt;li&gt;They just &lt;em&gt;pile-up&lt;/em&gt; and &lt;em&gt;quickly&lt;/em&gt;!&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This leads to eventual sadness:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sh-session" data-lang="sh-session"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="go"&gt;sign_and_send_pubkey: signing failed for ED25519 &amp;#34;key-abc&amp;#34; from agent: agent refused operation
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="go"&gt;Received disconnect from 10.x.x.1 port 22:2: Too many authentication failures
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I&amp;rsquo;ve mentioned this problem to ChatGPT from time to time and it has
historically hallucinated promising but ultimately disapointingly
nonsense &amp;ldquo;solutions.&amp;rdquo;&lt;/p&gt;</description></item><item><title>Automation, I dig it!</title><link>https://ineptitude.ca/writing/i-dig-it/</link><pubDate>Sat, 29 Nov 2025 00:00:00 +0000</pubDate><guid>https://ineptitude.ca/writing/i-dig-it/</guid><description>&lt;p&gt;&amp;hellip;and just like that, we&amp;rsquo;re live with automated publishing. I commit to git and a CICD pipeline authenticates over OIDC and deploys to an S3 bucket that serves as an origin for CloudFront. The domain is hosted on Route53 using DNS records created and maintained by Terraform.&lt;/p&gt;
&lt;p&gt;I push&amp;hellip; content gets published. What more can you want? I think this is going to work out just fine, indeed!&lt;/p&gt;</description></item></channel></rss>