Hacker News new | past | comments | ask | show | jobs | submit login

> Don't expose SSH to the entire internet [...]

Yes, and that's what tools like tcp wrapper (or iptables) are there for. I use it to disallow whole networks from Brazil, China, etc so they don't even reach sshd to talk to it. Less log clutter, less to do for fail2ban if installed.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: