Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Adding to that, some servers might have a secondary user with a weak password that was created by an installer or an admin for testing purposes. Disallowing password login prevents others from exploiting these accounts.


Agreed, that's why I put "If you are running a server where only you SSH in" but maybe I should have been more clear about it.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: