4 ms·
We shouldn't expose sshd to the open internet? Should I be wary of services that do?
by sixcorners 15y ago
We shouldn't expose sshd to the open internet? Should I be wary of services that do?
- adestefan 15y agoI'd argue that the audited security of OpenSSH is better than most VPN solutions.
- StavrosK 15y agoSure, but there are still configuration problems. I remember having once set the root password to "", thinking it will lock everything out. Turns out that it only locks it for login, but not email server authentication. Someone managed to send emails as root@mybox, logging in with a blank password. I realize this isn't OpenSSH, but there will always be stupid users. Exposing as little as you can is a good idea.