4 ms·
Always use multiple layers of defence. A sturdy 6ft fence and a locked wooden front door can be more secure than a 50m impenetrable stone wall, if it turns out
by theginger 3y ago
Always use multiple layers of defence.
A sturdy 6ft fence and a locked wooden front door can be more secure than a 50m impenetrable stone wall, if it turns out that there is no such thing as an impenetrable stone wall.
Brute force protection is completely unnecessary for openssh when you've disabled password authentication because it's impossible[really expensive] to brute force.
Until you are impacted by an authentication vulnerability which still requires a valid user, then you are brute forcing a user away from being totally compromised. All of a sudden doing all the "unnecessary" things, like brute force protection, disabling root logins and not using default accounts make the difference between you being at the front or back of the line to get compromised in the race to get patched.
If you are one of those who believes a vulnerability like that is extremely unlikely rather than inevitable, then consider this. An ssh key gets leaked, the system it has access to is known / discoverable, the username is not. Brute force protection is now the main difference between being highly at risk and still reasonable safe.
It's a contrived scenario, but hardly an outrageous one.
- o11c 3y agoA sturdy 6-foot fence keeps your yard looking nice, even if you still have to lock the front door.