I would argue that this approach is more "security by obscurity" than any useful analogy to quantum mechanics. Whatever vulnerability that remote access presents does *not* go away when something external to the system changes. It's easier to see the flaw in thinking if you consider passwords rather than a complex key pair exchange. If I have a password like 'sexy123', anyone who can either guess it or hack my local password database can use it to access the remote system. Deleting it from my local system and acting like the remote system is now secure is extraordinarily short sighted. > as long that private key exists on my laptop, that server has a vulnerability It is more correct to say that the server shares the laptop's vulnerabilities *any time after* that access was set up. Along with all other vulnerabilities that are introduced in the process (e.g., backups, etc.). Nothing "spooky" is happening, and systems *will* get exploited if they are not properly maintained. 8b7b4832bf0459fa32cb99b786a24ab97984ed3a5f675669638a81b07472cfe9