
JAuth (John’s Auth) is my own system for storing SSH keys. I believe logging in to a server should take two things: something you know and something you have, meaning a hardware device that signs for you. There are already ways to do this. A YubiKey is one, and Google makes similar devices. If your security needs are strict, a YubiKey is honestly still the best choice. But in my day-to-day life I forget my YubiKey at home. Even with a tracking tag on it, I usually don’t get the alert until I’m miles down the road. I almost never forget my phone. That’s the idea behind JAuth.
How it works. Your SSH keys live on your Android phone in an encrypted vault, locked by a key that Android’s hardware-backed Keystore protects. (GrapheneOS gives you the best support.) Your computer talks to the phone over an encrypted Bluetooth channel. When ssh needs a signature, the phone asks whether to allow the login and shows where it’s going. You confirm with your fingerprint, face or PIN. The phone signs, and you’re in. The private key never leaves the phone.
New phone? No problem. You can export your keys from the app into an encrypted backup file. Restore it on the new phone, or keep it on an air-gapped machine. Again, if you need keys that can never be copied, get a YubiKey.
Supported computers. jauthd is the small background program that talks to the phone over Bluetooth and serves your keys to SSH.
Windows: Windows’ built-in OpenSSH, and PuTTY through a Pageant-compatible agent.
Linux and macOS: a standard SSH_AUTH_SOCK socket.
Before you start: the phone
- Install the JAuth app (coming soon) on your Android phone.
- Create a key in the app, or import one you already have.
- Each computer gets paired with the phone once (the steps are below). After that it reconnects on its own.
Get a cheap good Cell Phone Plan (if you sign up I get a credit)
