3 ms·
I want to like DigitalOcean but it seems their attitude to security is rather lax, see e.g. http://digitalocean.uservoice.com/forums/136585-digital-ocean/sugges
by dgl 13y ago
I want to like DigitalOcean but it seems their attitude to security is rather lax, see e.g. http://digitalocean.uservoice.com/forums/136585-digital-ocean/suggestions/3667114-generate-ssh-host-keys-for-new-droplet http://digitalocean.uservoice.com/forums/136585-digital-ocea... which they said they'd look at in February but haven't addressed.
- raiyu 13y agoThis was resolved, thanks for highlighting it, need to get this uservoice entry updated. Also we launched two factor auth recently. We take security very seriously. Thanks
- dgl 13y agoIt doesn't look resolved to me, check the key fingerprint on any Ubuntu 12.04 x64 server droplet: ECDSA key fingerprint is 97:d7:21:81:9b:77:34:bb:f1:8e:86:25:b0:47:6b:ff. Also: -rw------- 1 root root 227 Apr 25 2012 ssh_host_ecdsa_key
- pfg 13y agoI can confirm this on a Ubuntu 12.04 x64 droplet created 15 days ago.