frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Is Connecting via SSH Risky?

3•atrevbot•1h ago
I have been managing websites for a while and usually utilize SSH connections to login to, deploy code to, and otherwise remotely access the hosting servers.

I was recently informed that a client I work with considers that a legal risk.

If the SSH connection is set to disallow passwords and only authorize via SSH keys, how big of a risk is this?

Comments

phren0logy•1h ago
Compared to what?
DamonHD•1h ago
Indeed.
atrevbot•1h ago
They seem to be okay w/ only HTTP ports being open on the server (80, 443). They "found that open ports can lead to cyber claims".
bediger4000•16m ago
That's like saying that open bottles lead to alcoholism.
robertcope•33m ago
How else would you do it?
rl3•21m ago
Best practices usually call for not exposing the SSH endpoints to the public internet. The principal risk is vulnerabilities in the underlying SSH server implementation. Historically, critical flaws that can compromise you are few and far between. However, these days AI is already starting to become adept at reverse engineering.

If you must, you'd typically use a bastion host that's configured just for the purpose of handing inbound SSH connections, and is locked down to a maximal degree. It then routes SSH traffic to your other machines internally.

I'd argue that model is outdated though, and the prevailing preference is putting SSH behind the firewall on internal networks. Think Wireguard, Tailscale, service meshes, and so on.

With AWS, restricting SSH ports via security groups to just your IP is simple and goes a long way.

verdverm•18m ago
Runs counter to my understanding, I'd ask for clarification and find support material to show your approach is safer.

Treat it as a teaching moment for them

speleolinux•17m ago
If your private key has a good passphrase and is suitably encrypted, say with ed25519, then that's probably as good as you can do other than physically going into work and storing everything in your head :-) Politely ask the client to suggest what they consider would be a suitable alternative. I also setup git hooks to prevent accidentally checking in private keys or passwords into git or other version control systems. And if I'm travelling into or from work I also encrypt some stuff just in case I have a problem and the laptop is stolen.

MLM Software Development

1•sonniya•12s ago•0 comments

Is AI the Next Climate Change?

https://www.wsj.com/opinion/is-ai-the-next-climate-change-e7a11637
1•apparent•1m ago•0 comments

Show HN: Skill Gen: A meta skill for auto-generating skills from docs

https://www.railly.dev/blog/skill-gen/
1•Hunter17•1m ago•0 comments

We built a serverless GPU inference platform with predictable latency

1•QubridAI•1m ago•0 comments

Bridge AI with SKills

https://bridge.surf/
1•Johnson8053•2m ago•0 comments

Show HN: Anoncast: Turn Blogs into Podcasts

https://www.anoncast.net/
1•nbaronia•6m ago•0 comments

InvoiceBingo

https://www.invoicebingo.com
1•vesirak•6m ago•0 comments

Game Boy Advance Audio Interpolation

https://jsgroth.dev/blog/posts/gba-audio-interpolation/
1•zdw•7m ago•0 comments

When internal hostnames are leaked to the clown

https://rachelbythebay.com/w/2026/02/03/badnas/
1•zdw•8m ago•0 comments

Replit's Recent Pricing Change Is About Trust, Not Credits

https://flexprice.io/
2•NIKHILFP•8m ago•1 comments

Study: Older Cannabis Users Have Larger Brains, Better Cognition

https://news.cuanschutz.edu/news-stories/study-finds-cannabis-usage-in-middle-aged-and-older-adul...
1•emptybits•12m ago•0 comments

NASA acknowledges the elephant in the room with the SLS rocket

https://arstechnica.com/space/2026/02/nasa-finally-acknowledges-the-elephant-in-the-room-with-the...
1•knappe•17m ago•0 comments

New DeepSeek Research – The Future Is Here [video]

https://www.youtube.com/watch?v=fFL7la73RO4
1•chii•19m ago•0 comments

ICE seeks industry input on ad tech location data for investigative use

https://www.biometricupdate.com/202602/ice-seeks-industry-input-on-ad-tech-location-data-for-inve...
35•WaitWaitWha•28m ago•2 comments

Claude Cowork and the Case of SaaSpocalypse

https://gpt3experiments.substack.com/p/claude-cowork-and-the-case-of-saaspocalypse
3•nutanc•36m ago•1 comments

Show HN: An AI-Powered President Simulator

https://presiduck.feedscription.com/
5•tzhu1997•37m ago•0 comments

Astronauts Are Going Back to the Moon for the First Time in Half a Century

https://time.com/7346146/artemis-ii-launch-nasa-astronauts-moon-mission/
2•helloplanets•45m ago•0 comments

The CIA Is Sunsetting the World Factbook

https://actualityabridged.substack.com/p/the-cia-is-sunsetting-the-world-factbook
6•blizow•46m ago•0 comments

Climate Change Economic Models Omit Shocks, Likely Flawed

https://www.theguardian.com/environment/2026/feb/05/flawed-economic-models-mean-climate-crisis-co...
3•stego-tech•51m ago•1 comments

Show HN: A text format for UI wireframes – comparing token costs across 4 format

https://github.com/enlinks-llc/katsuragi
2•enlinks•53m ago•0 comments

Show HN: FIPSPad – a FIPS 140-3 and NIST SP 800-53 minimal Notepad app in Rust

https://github.com/BrowserBox/FIPSPad
2•keepamovin•53m ago•1 comments

Mick Jagger "Memo from Turner" (1970) [video]

https://archive.org/details/memo-from-turner-clip
2•petethomas•57m ago•0 comments

Show HN: Use Claude Code to Query and Analyze Your Finances

https://github.com/theFong/mmoney-cli
1•alecfong•1h ago•1 comments

4-Hour Builds: Anatomy of a Developer Experience Collapse

https://fabioluciano.com/en/4-hours-build-anatomy-devex-collapse/
1•fabioluciano•1h ago•0 comments

Spellcasting

https://phyous.github.io/spellcasting/
2•wpnx•1h ago•0 comments

OpenClaw Is Lonely [video]

https://vimeo.com/1160861583
1•laserduck•1h ago•0 comments

Strava removes 2.3M rides from leaderboards in clampdown on cheats

https://www.cyclingweekly.com/news/strava-removes-2-3-million-rides-from-leaderboards-in-clampdow...
2•brippalcharrid•1h ago•0 comments

Constant 14ms attention: 512→524K tokens (24.5x faster than FlashAttention)

https://github.com/RegularJoe-CEO/vllm/blob/waller-operator-integration/benchmarks/attention_benc...
1•luxiedge•1h ago•1 comments

Sequoias Need for Churn

https://www.gnupg.org/blog/20250117-aheinecke-on-sequoia.html
1•mocknen•1h ago•0 comments

Investigators found 'concerning similarities' between Reedley, Las Vegas labs

https://abc30.com/post/investigators-found-concerning-similarities-between-reedley-las-vegas-labs...
3•petethomas•1h ago•0 comments