maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Newbie (https://talk.maemo.org/forumdisplay.php?f=26)
-   -   SSH and root access (https://talk.maemo.org/showthread.php?t=15810)

Milhouse 2008-01-30 19:47

Re: SSH and root access
 
Quote:

Originally Posted by caseyd (Post 135830)
Will I create new problems if I add a password to the user account?
I would rather be able to get into my 810 from anywhere, w/out doing the certificate management dance first.

It won't create a problem but you're making your device less secure - it's highly secure without a password, adding the password weakens the existing security.

The most secure option is to use public/private key authentication for the user account (as described in the thread I linked earlier) and disable logins on the root account (you can still sudo to root from the user account).

free 2008-01-30 20:20

Re: SSH and root access
 
^
|
|
Paranoiac


;p


edit:
After you've used ssh-copy-id, you can then remove the password of user
Do this as root:
usermod -L user

Lazy way of transfering keys..

froghunter 2008-05-04 19:58

Re: SSH and root access
 
Sorry, a bit of a noob, but wondering about why a user password weakens everything, and where would you even use it since there isn't a GDM or anything like that (which btw would be pretty nice). Also, if you change your root password and then disable root login, will it ask for a password when you sudo gainroot? Thanks a lot, I appreciate it.

mwiktowy 2008-05-04 20:46

Re: SSH and root access
 
Quote:

Originally Posted by froghunter (Post 177891)
Sorry, a bit of a noob, but wondering about why a user password weakens everything, and where would you even use it since there isn't a GDM or anything like that (which btw would be pretty nice). Also, if you change your root password and then disable root login, will it ask for a password when you sudo gainroot? Thanks a lot, I appreciate it.

Password authentication is only as strong as the password picked and many people pick weak passwords. So that makes it vulnerable to brute-force attacks to guess your password. Key-pair authentication is essentially immune to this since the size of the key to guess is much, *much* bigger yet you don't have to keep it in your head to be used.

Also if you are not typing in a password, neither someone looking over your shoulder nor a keylogger running on your system or attached to a keyboard cable or sniffing bluethooth signals will allow an attacker to gain access.

So whether you set this up depends on your degree of security required but it is a pretty good trade-off between more security and ease of logins down the road vs. a little bit of up-front pain in getting it all configured right.


All times are GMT. The time now is 14:48.

vBulletin® Version 3.8.8