Comment by niij
10 years ago
>If you're already running an SSH server, a non-root app can most likely edit your ~/.ssh/authorized_key file. It's just a regular file, nothing special about a malicious app adding an entry to it.
That file is -rw-r--r--, so only the owner or root can change it, unless I am misunderstanding you?
That app is running as you, so it is the owner of the file at that point.
You're absolutely right.