Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ping and ssh are pretty much never the things being hacked though. Turn password auth off and it’s very secure.

What gets hacked all the time is the actual web app itself. Which has to be exposed to be useful.



I imagine it pays off to find weaknesses in openssl and sshd and the other gateways. There are some ubiquitous web frameworks, but ssh is nearly universal.


> Turn password auth off and it’s very secure.

Password auth and the root username. Use one attackers are unlikely to guess and elevate with sudo if needed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: