Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
DaniloDias
on Jan 16, 2020
|
parent
|
context
|
favorite
| on:
Pwning your web server the easy way or why exposin...
TL;DR: Antipattern: pointing web server config to any files based in /home.
asveikau
on Jan 16, 2020
[–]
Not just that. Even if you don't make that mistake, having servers ssh into other hosts and leaving keys on them for this purpose means if one machine is compromised, others can be too. And they can use known_hosts to discover which ones.
arpa
on Jan 17, 2020
|
parent
[–]
ssh -A is a thing. A risky thing, but so much better than keeping private keys on server.
Join us for
AI Startup School
this June 16-17 in San Francisco!
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: