4 ms·
Since wireguard is a thing now wouldn't it be inadvisable for new deployments to put ssh on the bare internet anyway?
by gxt 4y ago
Since wireguard is a thing now wouldn't it be inadvisable for new deployments to put ssh on the bare internet anyway?
- Gasp0de 4y agoWhy exactly is wireguard safer than ssh with keys?
- chlorion 4y agoThis is an interesting question. I would say at the very least it offers an extra layer of authentication over ssh, so it would require a wireguard bug and ssh bug to cause damage. That alone provides extra security! Another helpful thing, is that wireguard doesn't respond to invalid connection attempts at all. An invalid connection attempt appears as if you are accessing a port that nothing is listening on! Because of this, you can't detect what port wireguard is listening on, or even if it's running at all, so mass scanning the internet for wireguard listening ports and attempting connections is extremely ineffective. There are probably other aspects that make it safer. You can read a lot about wireguard here https://www.wireguard.com/papers/wireguard.pdf https://www.wireguard.com/papers/wireguard.pdf
- attentive 4y agoThis is correct answer. No reason to expose ssh to the internet.