Posted by atrevbot 2 days ago
Ask HN: Is Connecting via SSH Risky?
I was recently informed that a client I work with considers that a legal risk.
If the SSH connection is set to disallow passwords and only authorize via SSH keys, how big of a risk is this?
If you are using only keys, make sure they are managed, tracked, securely stored and backed up. The last thing you want is to have a machine die that has the only private key for your environment.
But yeah putting it behind some kind of VPN is advisable if anything because of all the driveby nuisance attacks on ipv4.