4 ms·
I have seen a lot of failed connection attempts in my logs, but never noticed substantial resource usage. Is SSH DoS a serious concern? I get the impression peo
by ahepp 3y ago
I have seen a lot of failed connection attempts in my logs, but never noticed substantial resource usage. Is SSH DoS a serious concern? I get the impression people are suggesting it to protect authentication, which makes basically zero sense to me.
- dreamcompiler 3y agoF2B shrinks the attack surface. There's almost no chance of somebody getting in if you secure your server properly, but "almost no" is not zero, and making it even closer to zero seems like a good idea. My main concern is that some future update to SSHd will contain a zero-day vulnerability and F2B would at least slow the bad guys down. My second concern is that I might spin up a server and forget to disable SSH passwords and leave one enabled that happens to show up in a password database. Oof.