Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m confused; Your entire response seems like reasons to not do this.


None of them apply to the situation of an individual operating an accessible system for their own use, or very small business with a handful of employees.

The kind of organization where it would make sense to forbid tricks like multiple password entries pointing to the same user (such as UID 0) is going ot be the kind of organization where the whole thing is moot anyway in connection with SSH, because in those kinds of organizations, you don't want ad hoc machines to be accessible via SSH publicly. You don't want employees to be solving the problem of SSH ports being probed: do we use fail2ban, port knocking, kazinator's user name tricks posted on HN? ... just no! You have some kind of perimeter VPN. Authorized users connected to the VPN can then use SSH to machines inside the secured zone.

It makes no sense to bring up corporate rules against my solution which for a problem that corporations should not have in the first place: SSH-accessible machines on the open internet being probed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: