Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why disallow root login? What's wrong with allowing root login via public key only? Or via a public key limited by command="..."?


It's good practise first login as another user and then gain root priv's. This is auditable and if your sshd won't allow root login's, the can't be brute forced directly.


Do you ever need root login?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: