Got the Windows10 Pro additional feature "OpenSSH-Client" which includes ssh-agent functionality. Keys can be added to the agent with ssh-add. Much to my surprise this Windows implementation seems to store these private keys ON DISK - standard ssh-agent will only store them in RAM. Just try this:
ssh-add <private key from thumbdrive>
## remove thumbdrive
## stop ssh-agent service
## start ssh-agent service
ssh-add -l
And, Lo and Behold, keys are still there; even reboot won't wipe them!
So now my really, really secure private keys are somewhere on the system disk. How can I erase them and any relics that might be still on disk? Does anyone know the location where these are kept?
BTW. personally, I find this a bad feature extension to the original OpenSSH ssh-agent