I didn't know you were supposed to disable root user... - eviltoast

Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

  • MyNameIsIgglePiggle@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    1 day ago

    Since I’ve switched to using SSH keys for all auth Ive had no problems I’m aware of. Plus I don’t need to remember a bunch of passwords.

    But then I’ve had no training in this area. What do I know