3 ms·
You expose VPN to the internet, and expose SSH access just to the private VPN. You can still use SSH keys for your SSH auth, but now with the added layer of lis
by BossingAround 2y ago
You expose VPN to the internet, and expose SSH access just to the private VPN. You can still use SSH keys for your SSH auth, but now with the added layer of listening only on the VPN network.
Isn't that strictly better? I.e. even if an attacker exploits a vulnerability to get to your private VPN network, they now have to find another exploit to get SSH access (presumably with the same SSH keys setup).
Edit: Aaah, the VPN isn't a private VPN, but Raspberry Pi Foundation's VPN, to use some of their solution to get to your RPI, right? In that case, I agree, the attack vector is just larger. I was confused because the article mentions a private VPN that Jeff has set up himself.
- marcus0x62 2y ago> Isn't that strictly better? I think that greatly depends on the VPN. For something like Wireguard with a tiny attack surface? Sure, you can make that argument. For something big and sprawling like a commercial VPN (or even something open source like OpenVPN) - I think unless you have some other reason to run that VPN system anyway, the VPN probably has more attack surface than OpenSSH (and, in all likelihood, a worse security record to boot.) Also, consider that if you are running the VPN server on the same system as the SSH daemon, an attacker generally wouldn't need to compromise the SSH daemon after compromising the VPN server - they'd probably already have a root shell just from popping the VPN.
- op00to 2y agoLayered security is good, but you're still using a key to access a resource. Looked at individually, using a key to access a VPN is not more secure than using a key to access SSH. The risk isn't a remotely exploitable bug in ssh, but losing your secrets due to some other vulnerability. If someone has access to your SSH key, they almost certainly are able to also access your VPN key - both are saved in your home directory and need to be regularly accessible. If, maybe, your VPN uses two factor authentication, that makes it much harder, but you could also use two factor authentication for SSH, and we're back to where we were before.