3 ms·
I think Amazon does a good job here. Default SSH is with certificates, passwords not used. I like that. Hard to brute force a certificates. In the old flat 1
by glzone1 2y ago
I think Amazon does a good job here.
Default SSH is with certificates, passwords not used. I like that.
Hard to brute force a certificates.
In the old flat 10.X.X.X network amazon days - your new hosts were absolutely hammered when being brought up. There must have been folks on the amazon network itself just portscanning like crazy.
- kevincox 2y ago> Hard to brute force a certificates. I see this mentioned a lot. But is it any harder to brute force a 2048 certificate than a 2048 bit password? (Note: A 2048 bit password with base64 character set is 342 characters long) Don't get me wrong, there are many advantages to certificates (server doesn't learn the secret, easier to enforce strong secrets, ability to issue centrally, ...) but there is nothing magically different between a certificate and password when it comes to resistance to brute force. If you generate a high-entropy password you are fine from this point of view.
- glzone1 2y agoAt least in government there often were weird limits on password length (ie, 8, 40, 72 ) or in tooling around passwords. Certificates seem to force allow things like 2048 bits. Didn't Red Hat have a default at 8 for a while??
- kevincox 2y agoYeah. But if you can afford to store a certificate of that size you can afford to store the password. Also worth noting that for most types of certificate (like RSA where 2048 bit keys are common) there is much less than 2048 bits of entropy. So in practice the numbers probably end up much closer.