4 ms·
Port obscurity is pointless when there's much better ways to secure your host. You should be running SSH with keys only, never with password authentication. P
by poutine 16y ago
Port obscurity is pointless when there's much better ways to secure your host.
You should be running SSH with keys only, never with password authentication. Passwords are for encrypting your keys on your local machine and for sudo which is restricted to specific accounts. Source IP filters really slow you down, but may work in some circumstances.
As your network gets larger you'll need to restrict any inbound SSH and use a VPN to a firewall or bastion host and use something like puppet to distribute your ssh keys. Make sure you do two factor auth to the VPN with a password and at least some sort of key.
- jwatzman 16y agoSource IP filters really slow you down Can you elaborate on this or provide a reference? I've never heard this before and am curious what the implications of various iptables filters are.
- jefe78 16y agoUsing keys isn't always an option. Passwords are a necessary evil in SOME cases. Which is to say, keys are ideal when appropriate.
- njharman 16y ago> Port obscurity is pointless when there's much better ways to secure your host. Good security is layered. This reduces attacks. Reducing attacks is better. Changing port is better than not changing port. And most people posting here obviously didn't read the article because it clearly stated this was in addition to all the other security measures you put into ssh.