5 ms·
It's not "death to SSH", it's "death to SSH over public Internet". Instead, what you'll want to be doing is SSH over WireGuard.
by CiPHPerCoder 8y ago
It's not "death to SSH", it's "death to SSH over public Internet".
Instead, what you'll want to be doing is SSH over WireGuard.
- ekianjo 8y agohow is that a security issue if you use your own computer with its own ssh keys?
- CiPHPerCoder 8y agoI think lvh's comment here is more appropriate for mature sysadmins who actually use key auth: https://news.ycombinator.com/item?id=17091990 https://news.ycombinator.com/item?id=17091990
- spacenick88 8y agoBut my SSH already uses Public Keys and ChaCha20/Poly1305 so that's really the last protocol I worry about sending through hostile territory
- atonse 8y agoWith Wireguard I believe you can go further and your servers can have only private IPs. And it's all seamless.
- pritambaral 8y agoBut the servers have to have a public IP to terminate the wireguard link, or be connectable from a machine that does. Exactly like SSH, be it via a bastion host or direct.