Skip to content

Comment on The OpenSSH Bug That Wasn't

Comments

Thankfully my use of PAM is for 2FA with SSH when I don't have my key. So they wouldn't have been successful in pulling off a bruteforce anyway. But it's annoying that their attempts weren't being limited as it can waste resources...

You wouldn't have a working config at hand for requiring TOTP (Google Authenticator) only for OpenSSH password logins on Debian, would you?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.