5 ms·
The more I learn, the more I find that “best practice” isn’t always best. It should be called good defaults. For example “Disable ssh password auth and use key
by dhsysusbsjsi 4y ago
The more I learn, the more I find that “best practice” isn’t always best. It should be called good defaults.
For example “Disable ssh password auth and use keys”. It depends on your threat model. A good password can be secure and may in some cases be more secure than a stolen laptop containing id_rsa. SSH keys are more convenient but rely on physical security. It should be discussed as a trade off.
- dima_vm 4y agoAFAIK, it's possible to require both ssh keys and password.
- alias_neo 4y agoI've found the authentication options to be extremely flexible, thanks, I think to PAM[0]? With PAM, it's possible to configure any combination of authentication requirements, in any desired order, with optional steps etc. One can require password AND keys AND physical token, in that order, or password AND keys OR physical token, or any other combination they desire. With PAM, one could go as far as to write a module requiring them to whistle the scooby doo tune to unlock. [0]https://en.wikipedia.org/wiki/Linux_PAM https://en.wikipedia.org/wiki/Linux_PAM
- j-bos 4y agobest practice -> good defaults I really like your phrasing. Maybe "favorite defaults" to maintain both the original idea and the nuance.
- jeroenhd 4y agoBut then you can protect against both keyloggers and stolen laptops by enabling TOTP 2FA. You can even require all three! I have a bastion setup somewhere in my network that's locked behind either an SSH key or a password + TOTP token for when I lose access to all devices with a signed SSH certificate. All devices are encrypted and I don't lose sight of them in public so my threat model would include "the police" and "people violently breaking in and stealing my stuff" but a password isn't going to protect me from that.