home.social

#ssh — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ssh, aggregated by home.social.

  1. Túneles y Redes Privadas (VPNs vs. WireGuard)

    Montar un túnel SSH o levantar una red malla con WireGuard/Tailscale sigue siendo la navaja suiza de la infraestructura. Ocultar tus servicios detrás de túneles encrypted y exponer solo lo estrictamente necesario ahorra toneladas de ataques de fuerza bruta en el puerto 22. En redes, la superficie de ataque mínima siempre gana. 🔒

    #Networking #SysAdmin #WireGuard #CyberSecurity #DevOps #SSH

  2. SSH keys alone won't stop a stolen key. Add Google Authenticator 2FA to your Linux server so a login needs both. Step-by-step guide for Ubuntu at valtersit.com/guides/security/ #SSH #Linux #Security

  3. SSH keys alone won't stop a stolen key. Add Google Authenticator 2FA to your Linux server so a login needs both. Step-by-step guide for Ubuntu at valtersit.com/guides/security/ #SSH #Linux #Security

  4. SSH keys alone won't stop a stolen key. Add Google Authenticator 2FA to your Linux server so a login needs both. Step-by-step guide for Ubuntu at valtersit.com/guides/security/ #SSH #Linux #Security

  5. SSH keys alone won't stop a stolen key. Add Google Authenticator 2FA to your Linux server so a login needs both. Step-by-step guide for Ubuntu at valtersit.com/guides/security/ #SSH #Linux #Security

  6. Really loving the configurability of new-to-me #kde #kdeplasma

    That said, just found my first braindeadism. #cli #ssh **pops up a window** to ask for the password.

    literally why.

    but that's not even the braindead part. On the first contact, you are asked to confirm adding the hash, right? obvs you get a popup for that as well.

    BUT THE POPUP SAYS IT WANTS A PASSWORD

    If you type a password, it doesn't work (because the answer to the real question has to be "yes" or "no").

    You then get another popup that says it has to be "yes" or "no"....

    ...AND IT IS STILL LABELED "password"

    w
    t
    a
    f

    #linux #design

    (uninstall kssaskpass and unset SSH_ASKPASS* to make this idiocy go away)

  7. Really loving the configurability of new-to-me #kde #kdeplasma

    That said, just found my first braindeadism. #cli #ssh **pops up a window** to ask for the password.

    literally why.

    but that's not even the braindead part. On the first contact, you are asked to confirm adding the hash, right? obvs you get a popup for that as well.

    BUT THE POPUP SAYS IT WANTS A PASSWORD

    If you type a password, it doesn't work (because the answer to the real question has to be "yes" or "no").

    You then get another popup that says it has to be "yes" or "no"....

    ...AND IT IS STILL LABELED "password"

    w
    t
    a
    f

    #linux #design

    (uninstall kssaskpass and unset SSH_ASKPASS* to make this idiocy go away)

  8. Really loving the configurability of new-to-me

    That said, just found my first braindeadism. **pops up a window** to ask for the password.

    literally why.

    but that's not even the braindead part. On the first contact, you are asked to confirm adding the hash, right? obvs you get a popup for that as well.

    BUT THE POPUP SAYS IT WANTS A PASSWORD

    If you type a password, it doesn't work (because the answer to the real question has to be "yes" or "no").

    You then get another popup that says it has to be "yes" or "no"....

    ...AND IT IS STILL LABELED "password"

    w
    t
    a
    f

    (uninstall kssaskpass and unset SSH_ASKPASS* to make this idiocy go away)

  9. Really loving the configurability of new-to-me #kde #kdeplasma

    That said, just found my first braindeadism. #cli #ssh **pops up a window** to ask for the password.

    literally why.

    but that's not even the braindead part. On the first contact, you are asked to confirm adding the hash, right? obvs you get a popup for that as well.

    BUT THE POPUP SAYS IT WANTS A PASSWORD

    If you type a password, it doesn't work (because the answer to the real question has to be "yes" or "no").

    You then get another popup that says it has to be "yes" or "no"....

    ...AND IT IS STILL LABELED "password"

    w
    t
    a
    f

    #linux #design

    (uninstall kssaskpass and unset SSH_ASKPASS* to make this idiocy go away)

  10. Really loving the configurability of new-to-me #kde #kdeplasma

    That said, just found my first braindeadism. #cli #ssh **pops up a window** to ask for the password.

    literally why.

    but that's not even the braindead part. On the first contact, you are asked to confirm adding the hash, right? obvs you get a popup for that as well.

    BUT THE POPUP SAYS IT WANTS A PASSWORD

    If you type a password, it doesn't work (because the answer to the real question has to be "yes" or "no").

    You then get another popup that says it has to be "yes" or "no"....

    ...AND IT IS STILL LABELED "password"

    w
    t
    a
    f

    #linux #design

    (uninstall kssaskpass and unset SSH_ASKPASS* to make this idiocy go away)

  11. Happy race condition of SSHD and FRR that causes SSHD to crash on startup because the IP is not yet configured half of the time...

    /me configuring non_local_bind=1 now...

    #alpine #FRR #SSH

  12. Happy race condition of SSHD and FRR that causes SSHD to crash on startup because the IP is not yet configured half of the time...

    /me configuring non_local_bind=1 now...

    #alpine #FRR #SSH

  13. Happy race condition of SSHD and FRR that causes SSHD to crash on startup because the IP is not yet configured half of the time...

    /me configuring non_local_bind=1 now...

    #alpine #FRR #SSH

  14. Happy race condition of SSHD and FRR that causes SSHD to crash on startup because the IP is not yet configured half of the time...

    /me configuring non_local_bind=1 now...

    #alpine #FRR #SSH

  15. Docker для параноика: организация SSH-доступа для rootless-контейнера без передачи приватного ключа

    SSH-доступ используется во множестве сценариев — от работы с репозиториями до автоматизации и управления серверами. Но если приватный ключ доступен самому приложению, при компрометации процесса его можно украсть. Замена SSH на токен проблему не решает: это будет просто другой секрет, доступный тому же процессу. В статье разберём архитектуру на базе ssh-agent и rootless Docker, в которой процесс может полноценно пользоваться выданным SSH-доступом, но не получает сам приватный ключ. Это ограничение обеспечивается самой схемой доступа и сохраняется даже при компрометации ПО внутри контейнера. Особенно актуален такой подход для систем с ИИ-агентами и дополнительными API-слоями вроде MCP-серверов.

    habr.com/ru/articles/1087148/

    #Docker #rootless_Docker #SSH #sshagent #SSH_AUTH_SOCK #AI_agents

  16. Docker для параноика: организация SSH-доступа для rootless-контейнера без передачи приватного ключа

    SSH-доступ используется во множестве сценариев — от работы с репозиториями до автоматизации и управления серверами. Но если приватный ключ доступен самому приложению, при компрометации процесса его можно украсть. Замена SSH на токен проблему не решает: это будет просто другой секрет, доступный тому же процессу. В статье разберём архитектуру на базе ssh-agent и rootless Docker, в которой процесс может полноценно пользоваться выданным SSH-доступом, но не получает сам приватный ключ. Это ограничение обеспечивается самой схемой доступа и сохраняется даже при компрометации ПО внутри контейнера. Особенно актуален такой подход для систем с ИИ-агентами и дополнительными API-слоями вроде MCP-серверов.

    habr.com/ru/articles/1087148/

    #Docker #rootless_Docker #SSH #sshagent #SSH_AUTH_SOCK #AI_agents

  17. Docker для параноика: организация SSH-доступа для rootless-контейнера без передачи приватного ключа

    SSH-доступ используется во множестве сценариев — от работы с репозиториями до автоматизации и управления серверами. Но если приватный ключ доступен самому приложению, при компрометации процесса его можно украсть. Замена SSH на токен проблему не решает: это будет просто другой секрет, доступный тому же процессу. В статье разберём архитектуру на базе ssh-agent и rootless Docker, в которой процесс может полноценно пользоваться выданным SSH-доступом, но не получает сам приватный ключ. Это ограничение обеспечивается самой схемой доступа и сохраняется даже при компрометации ПО внутри контейнера. Особенно актуален такой подход для систем с ИИ-агентами и дополнительными API-слоями вроде MCP-серверов.

    habr.com/ru/articles/1087148/

    #Docker #rootless_Docker #SSH #sshagent #SSH_AUTH_SOCK #AI_agents