3 ms·
you’ll want to lock down SSH access entirely, and make sure that only you can get in This sounds like Ubuntu is by default open to everybody via ssh. I find
by itry 13y ago
you’ll want to lock down SSH access entirely,
and make sure that only you can get in
This sounds like Ubuntu is by default open to everybody via ssh. I find this hard to believe.
The whole article sounds like a lot of fud to me. For example, what benefit is there in creating a new user with sudo privileges instead of using root directly?
- scraplab 13y agoPotentially that if the key is compromised, the holder still requires a password before gaining root access. But if your key is compromised, you probably have a bigger problem.
- DanBC 13y ago> For example, what benefit is there in creating a new user with sudo privileges instead of using root directly? Users should run with as few privileges as possible. Logging in as root requires two sets of keys. Sudo logs all commands. The commands usable when using sudo can be limited, whereas root gives access to everything. Using sudo creates heightened awareness of risks. Root is a high value target. Giving it a strong password is important, but locking it is better.
- csears 13y ago> For example, what benefit is there in creating a new user with sudo privileges instead of using root directly? Also, when a group of people all need access to the same servers, you don't want everyone SSHing in as root. It's much easier to manage team security when everyone has individual users and sudo rights that can be logged and audited.