I don't think so. A single server sitting behind an advanced firewall/IDS/IPS system and managed by competent IT staff is a much harder target than a multitude of servers I manage myself.
Also note that it's not really an extra step, you put in a ProxyCommand in your .ssh/config file.
Comments
Doesn't that have all the problems of password auth, but with one extra step, with it's own failure modes, in between?
I don't think so. A single server sitting behind an advanced firewall/IDS/IPS system and managed by competent IT staff is a much harder target than a multitude of servers I manage myself.
Also note that it's not really an extra step, you put in a ProxyCommand in your .ssh/config file.