Readit News logoReadit News
atrevbot commented on Ask HN: Is Connecting via SSH Risky?    · Posted by u/atrevbot
_Chief · 4 days ago
> If the SSH connection is set to disallow passwords and only authorize via SSH keys, how big of a risk is this

low risk, do this. Keys (ed25519,4096 rsa) are impractical to brute force. However I'd also recommend:

- use a different port than 22 (add your .ssh/config for easier UX if needed) - port 22 can get incredibly noisy with tons of bots probing

- disable passwordAuth, disable PermitRootLogin - use a normal user with sudo for your ssh

- consider a vpn please - I use tailscale, but I hear headscale is good - then use UFW to only allow SSH from the tailscale network (I generally allow all network on tailscale). Tailscale wrote a guide on this here [1]

- do not add and forget authorized_keys from machines you arent using

- I'm especially worried about how people keep giving Clawdbot/Openclaw access to all their machines, key auth means the machine is authorized on your server

- For new servers I often just add all my public keys to them (github lists all your keys at github.com/GH_USERNAME.keys

1: https://tailscale.com/docs/how-to/secure-ubuntu-server-with-...

atrevbot · 4 days ago
Thanks a lot for the detailed response. I see Tailscale pop up here often and have been meaning to better understand how it could fit into my typical hosting setup, so I appreciate that reference.

For additional context I usually host on a shared or dedicated VPS, and in this case am managing a WordPress site I inherited. It seems to me that if the SSH connection is restricted by IP and limited to keys, there are much larger risks involved in hosting a WordPress site publicly available on the internet w/ dozens of plugin dependencies.

atrevbot commented on Ask HN: Is Connecting via SSH Risky?    · Posted by u/atrevbot
phren0logy · 5 days ago
Compared to what?
atrevbot · 5 days ago
They seem to be okay w/ only HTTP ports being open on the server (80, 443). They "found that open ports can lead to cyber claims".
atrevbot commented on US will ban Wall Street investors from buying single-family homes   reuters.com/world/us/us-w... · Posted by u/kpw94
Seattle3503 · a month ago
We need more rental units, and it isn't clear how that policy would help the situation.
atrevbot · a month ago
We need more houses for sales and this would incentive people to create it.
atrevbot commented on HealthBench – An evaluation for AI systems and human health   openai.com/index/healthbe... · Posted by u/mfiguiere
const_cast · 9 months ago
The only reason this worked is because your situation was exceedingly simple.

The trouble is you are not educated enough to tell what is simple and what isn't. A cough could be a cough or it could be something more serious, only a "real" examination will reveal that. And sometimes even that's not enough, you need an examination by a specialists.

I'll tell you a story. Once upon a time I got pain in my balls. I went to a doctor and he felt around and he said he didn't feel anything. I went to another doctor and he felt something, but he had no idea what it was. He said could be a cyst, could be a swollen vein, could be an infection - he didn't even know if it was on the testicle or on the tube thingy.

Then I went to a Urologist. You can tell this man has felt up a lot of balls. He felt me up and said, "yup, that's a tumor" almost immediately. He was right, of course, and he ended up being the one to remove it too. Since I caught the cancer pretty early the chemotherapy wasn't too intense.

Point is, expertise matters when things aren't straight forward. Then, experience and perspective gets to shine.

atrevbot · 9 months ago
As a competing anecdote, last summer my toddler woke up from a nap with bruises on his legs and swelling around his joints. We initially thought maybe he was tangled up in his crib, but later when changing his diaper found his testicles were swollen and rushed him to the emergency room. Over the next 6-7 days we saw no less that 5 doctors including his pediatrician, orthopedic specialists, and doctors at the ER and urgent care. None of whom were able to give us any answers about this weird bruising and swelling that randomly appeared on his legs. After all of this, during one of his flair ups, I took a picture of his legs and searched it with Google lens. The results set included pictures and symptoms of Henoch-Schonlein purpura [0], that were identical to what he was experiencing. We confirmed this with his pediatrician and decided on a treatment plan, but I was floored at how many doctors we had to see (and how much money we had to spend), only for me to diagnose this on my own with Google lens.

[0] https://www.mayoclinic.org/diseases-conditions/henoch-schonl...

atrevbot commented on Hardest problem in computer science: centering things   tonsky.me/blog/centering/... · Posted by u/tobr
lostlogin · 2 years ago
Tiles. There is a correct way to install them. I don’t know how you decide what’s correct, but sometimes it’s centred, sometimes a full one on the left, or the right.

Then you have the same scenario but top to bottom.

atrevbot · 2 years ago
When we were building our house I built a tool[0] for exactly this problem so I could visualize how tiles would look w/ different arranging. Worked really well for both floor tile and tile on the shower walls

[0] https://tilelayoutwizard.com/

atrevbot commented on Airlines will make $118B in extra fees   fastcompany.com/90981005/... · Posted by u/thunderbong
magneticnorth · 2 years ago
As for sitting next to a partner, if you don't absolutely need to guarantee it, then you can wait til you get to the airport and ask at the gate if they can move you to be beside each other.

If the plane is totally full you'll be out of luck, but if there's space then the gate agents will happily reassign you.

atrevbot · 2 years ago
On the flip side of this my partner and I recently decided to pay the additional fee to Spirit to ensure that us, our 6 year old, and our 18 month old (traveling on lap) could sit together. We paid extra to sit toward the front of the plane to minimize time on the plane after landing. As we were boarding we were told that we had been moved because the row we were in was the exit row and we could not sit there with a child (though they let us select that row no problem when they wanted more money). They reassigned us to the very last row on the plane with no window for our 6 year old and no refund on our seat selection fee. I will probably just take my chances asking at the gate next time.

u/atrevbot

KarmaCake day20June 11, 2019
About
Software developer in Charlotte, NC area.

Specializing in CMS web application development.

View Original