• StrixUralensis@tarte.nuage-libre.fr
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    Passwordless login only

    Never understood this

    I don’t think that anyone or anyrhing, computer or mentalist, will guess my 40+ characters long password

    • non_burglar@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      With ssh, over 90% of the vulnerabilities are abusing the password mechanism. If you setup pre-shared keys, you are preventing the most common abuses, including in the realm of zero days.

    • surph_ninja@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      Especially paired with Fail2Ban preventing any brute force attempts.

      But with a WireGuard setup, you need not have the port exposed at all.