3 ms·
b) use ssh, but control access with a firewall or vpn. c) fair enough, although you should probably be using keypairs and a vpn for test and dev envs too.
by oxymoron 8y ago
b) use ssh, but control access with a firewall or vpn.
c) fair enough, although you should probably be using keypairs and a vpn for test and dev envs too.
- xorcist 8y agoI see that recommendation a lot, but I'd expect most VPN products in use to be _less_ secure than a standard OpenSSH. It's a comparably less complex protocol and codebase than IPsec, for example, and pretty well audited by now. It's not as if VPN products hasn't been open to this type of attacks before (I'm looking at you, Cisco).