Home / Companies / Twingate / Blog / Post Details
Content Deep Dive

Your SSH Keys Are a Liability. Here's What Replaces Them.

Blog post from Twingate

Post Details
Company
Date Published
Author
-
Word Count
1,382
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Static SSH keys are portrayed as a growing enterprise security liability because they often lack expiration, centralized inventory, automatic revocation, MFA, and identity-linked auditing, leaving organizations with thousands of potentially privileged orphaned credentials after employees, services, or roles change. Citing research suggesting widespread gaps in SSH-key inventories and the prevalence of malware-free credential-based attacks, the discussion argues that a stolen or forgotten key can enable unnoticed access and lateral movement across many servers. It proposes replacing the static-key model with identity-brokered SSH access, where users authenticate through an existing identity provider and a gateway verifies identity, device posture, and policy for each session without placing long-lived credentials on devices or servers. Twingate Privileged Access for SSH is presented as an implementation of this approach, using clients, controllers, connectors, and a Layer 7 gateway to proxy and record authorized sessions while avoiding inbound server ports and shared jump-box access. The approach is said to simplify offboarding, strengthen centralized auditing, and support separate policies for emergency access and automation, while recognizing that SSH certificates improve on static keys but still require credential and certificate management.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 7 1,090 244 75 -24%
Kubernetes 1 3,185 361 109 +15%
Zero Trust 1 194 58 26 -23%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.