Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> root:root would be crazy, I would only use root:toor5 then I am secure for sure...

That's a minimal (read: insufficient) improvement, but if it were behind a real layer of security then it would strictly be an improvement.

> Side note, you should never allow login as root, and you should not really allow remote password login at either, only keys

I'm on board with keys, but why not allow root? If it's secured by a key, what's the harm?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: