Hacker News new | past | comments | ask | show | jobs | submit login

If you want password auth, you already have to change a default setting in SSHD and restart it. How exactly is removing that as a option ‘less complex’ for the downstream distros?



I don't really understand your question. Removing password auth reduces code complexity and therefore attack surface whilst also preventing users from using the software with a dangerous configuration. Maybe the users don't want that, but tough shit, maybe it's the nudge they need to use SSH keys.


In practice, this will just result in people and organisations using the last version of OpenSSH that supports password authentication.


Last time I checked "apt install openssh-server" on debian still launched sshd with password login enabled




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: