I know the majority decision is keys over passwords but every time I hear a security issue its over keys being stolen as typical malicious programs knows the standard go to place to grab them after getting you to sudo something evil. and the next response is you have time to change them before blah blah blah but attackers don't send you a email that says hey I have your keys! Wouldn't fail2ban with passwords be better for those who don't know how to manage every step of this ?
Comments
I know the majority decision is keys over passwords but every time I hear a security issue its over keys being stolen as typical malicious programs knows the standard go to place to grab them after getting you to sudo something evil. and the next response is you have time to change them before blah blah blah but attackers don't send you a email that says hey I have your keys! Wouldn't fail2ban with passwords be better for those who don't know how to manage every step of this ?