

9·
21 days agoPasswordless login only. No root login. Fail2ban. Add ufw to stop accidental open port shenanigans, and you are locked down enough
Passwordless login only. No root login. Fail2ban. Add ufw to stop accidental open port shenanigans, and you are locked down enough
Fair enough, it lowers the risk. Are you doing key stretching? Ie. X rounds of pbkdf or whatever it’s called?
I feel like saving the password in the export is a bad idea if security is your thing
Felt a bit like a faff to me, so I never bothered. Does depend upon your threat model though