this post was submitted on 28 Nov 2023
3 points (100.0% liked)

Self-Hosted Main

517 readers
1 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

For Example

We welcome posts that include suggestions for good self-hosted alternatives to popular online services, how they are better, or how they give back control of your data. Also include hints and tips for less technical readers.

Useful Lists

founded 2 years ago
MODERATORS
 

i want to remotely ssh to my home server, and I was wondering if I could just forward port 22 with disabling password login and use pubkey authentication will be safe enough?

you are viewing a single comment's thread
view the rest of the comments
[โ€“] tanjera@alien.top 1 points 1 year ago

Port forwarding opens an attack surface- whatever service you're exposing is the "attack surface" so make sure it's secure.

disabling password login

This is absolutely a very strong/good hardening first-step.

pubkey authentication

Hell yeah. Very strong. Just keep that key safe (don't post it on the Internet, put it somewhere insecure or public, etc. Also recommended to password protect the key for extra safety.

Additional steps you could take if you were worried: two-factor authentication, usually easy to setup and effective. Fail2ban or other IP blockers, takes more work and setup. Rate-limiting is a basic feature most ssh services have (e.g. more than 3 failed attempts = 5 minute lockout).

But honestly keys-only, IMHO, is the safest ๐Ÿ‘