The shortcuts and their price
| Shortcut | Convenience | Price |
|---|---|---|
NOPASSWD in sudoers | No prompt at all | Whoever gets your shell gets root; the second barrier is gone |
sudo -S with a piped password, sshpass, expect scripts | Works unattended | The password sits in a script, in the shell history or in the process list |
A longer timestamp_timeout | Fewer prompts per session | A longer window in which an unattended terminal is root |
| Copy from a password manager | The password stays strong and unique | Two window switches per prompt; the clipboard holds the password |
| A console that answers the prompt | One click, or none | The password is stored on your PC, so how it is stored matters |
How prompt answering works
The SSH console of the RDP FIDO client keeps password records. A record holds a name, the password and the text of the prompt it answers — for example [sudo] password. When the terminal prints a password prompt that contains that text, a small tile offers the matching record; one click types the password and Enter.
Tick “Type it by itself” and the record answers its prompt without the click — but not more often than once in 15 seconds, so a wrong password is never typed three times in a row.
The same mechanism answers the login password prompt and Enter passphrase for key….
Where the password lives
- Encrypted by the system: DPAPI of the current Windows user; on Linux, the desktop keyring.
- Optionally under a master password. Set one for the client, and saved passwords are additionally encrypted with AES-256-GCM under a key that exists on disk only wrapped by that password (PBKDF2-SHA256, 600,000 iterations). Another program running under your account then finds ciphertext, not the password.
- Never in the panel's page, never in the AI assistant's context. The panel names a record and the program types it; the terminal does not echo it.
- Per server or shared. A record can be limited to one session.
Set it up
- Install the RDP FIDO client on Windows 10 or 11. The console uses the OpenSSH client that ships with Windows, so your keys and
~/.ssh/configkeep working. - On the SSH tab add a session: the server address, your login, the “SSH console” protocol. A gate is optional — without one it is a plain SSH console.
- Open the session, go to the “Passwords” tab and add a record: the sudo password and the prompt text
[sudo] password. - Run any
sudocommand. The tile appears; click it — or tick “Type it by itself” in the record.
To try the console before adding a server, run RdpFidoClient.exe console with no arguments: it opens on a local shell.
The commands you type every day
The “Commands” tab holds the other thing admins retype: journalctl -u nginx -n 100 --no-pager, docker compose pull && docker compose up -d, a multi-line check script. A click runs a command; “Insert” types it without Enter, so you can add arguments. Commands belong to one server or to all of them.
When not to store it
- On a shared or unmanaged PC.
- Where policy forbids stored administrator passwords: keep typing, or keep them in a vault with its own hardware-backed unlock.
- In automation. A scheduled job should not answer an interactive prompt at all — give it a narrowly scoped sudoers rule instead.