Infrastructure nerd, gamer, and Lemmy.ca maintainer

  • 1 Post
  • 49 Comments
Joined 2 years ago
cake
Cake day: June 22nd, 2023

help-circle


  • Shadow@lemmy.catoLinux@lemmy.worldSSH backdoor infection
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 months ago

    Most don’t create new keys per server machine but that’s not the issue. I don’t bother, I create a key per client machine on my side.

    Server gets compromised once, admin logs in and fixes it, admin logs in next time and the backdoor compromises it again.

    That’s all this is. If you can get in once, it’s a spot you can leave a backdoor that many admins will miss. That’s it.

    Admins don’t generally copy that whole file around, they usually copy and paste the lines they want. Also I generally copy and paste it from my workstation, not another server.


  • Shadow@lemmy.catoLinux@lemmy.worldSSH backdoor infection
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    edit-2
    2 months ago

    If your hosting is a bad actor, you’re screwed no matter what. Why bother with this when they have direct access to your disk and ram

    You could turn off authorized key files, or lock them down. This isn’t really a big security risk though, there’s countless ways to backdoor a system once you have access to do this.

    This just targets a remote account, not your local pc.







  • Shadow@lemmy.catoSelfhosted@lemmy.worldIdeal Business Stack?
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    5 months ago

    You could do something like nextcloud to solve a lot of issues, but I’d still hesitate to recommend on-prem hardware and managing hardware yourself. It really comes down to the business tolerance for outages though, maybe the computers being down for a day or two doesn’t matter.


  • Shadow@lemmy.catoSelfhosted@lemmy.worldIdeal Business Stack?
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    5 months ago

    Are you providing a support contract long term? Are you backed by multiple people in case you’re away and their business is down? I say this more figuratively than specifically you, this could also apply to their internal IT guy who wants to do this.

    I’d strongly suggest deferring to a local business IT services company, unless you’re an active partner in the business. They should find a company they are comfortable with and trust, then use the products they recommend and are comfortable with.