Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


OFFICIAL B-L-A-C-K-F-R-I-D-A-Y THREAD -- COMMUNITY ENDORSED! Take a peek! (RackNerd's Black Friday) - Page 879
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

OFFICIAL B-L-A-C-K-F-R-I-D-A-Y THREAD -- COMMUNITY ENDORSED! Take a peek! (RackNerd's Black Friday)

18768778798818821117

Comments

  • @jmaxwell said:
    Maybe it’s better to disable password based auth

    I only use SSH keys for auth, pass auth is 👎

    Thanked by 2Void froz
  • @MooCowGalaxy said:

    @jmaxwell said:

    Someone DDoSing the SSH port ?

    After further testing it seems to be my ssh client, works when I use ssh command. The SSH client seems to not like connecting to any hosts right now, maybe restarting my computer will fix it.

    He’s on strike

  • @jmaxwell said:
    Maybe it’s better to disable password based auth

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

  • @MooCowGalaxy said:

    @jmaxwell said:
    Maybe it’s better to disable password based auth

    I only use SSH keys for auth, pass auth is 👎

    Awesome

  • @MooCowGalaxy said:

    @jmaxwell said:
    Maybe it’s better to disable password based auth

    I only use SSH keys for auth, pass auth is 👎

    My friend was also having ssh keys and ssh restricted to his static ip, but he still got pwned

  • And another sad news :(

  • @sonu said:

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

    I use termius, like 1password but for SSH. Everything is encrypted and you need the master password to decrypt it, so I trust them.
    Also their pro plan is free with github student pack so :)

  • @MMzF said:

    @MooCowGalaxy said:

    @jmaxwell said:
    Maybe it’s better to disable password based auth

    I only use SSH keys for auth, pass auth is 👎

    My friend was also having ssh keys and ssh restricted to his static ip, but he still got pwned

    That won’t make it hack proof anyway

  • @MMzF said:
    And another sad news :(

    What seems to be that ?

  • @jmaxwell said:

    That won’t make it hack proof anyway

    Well nothing is hack proof ;) Just needs an exploit, social engineering or lots and lots of time

  • @MooCowGalaxy said:

    @sonu said:

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

    I use termius, like 1password but for SSH. Everything is encrypted and you need the master password to decrypt it, so I trust them.
    Also their pro plan is free with github student pack so :)

    Interesting. I'm on windows and use KeePass (Password Manager)+ Keeagent plugin + Putty to SSH. It's really fast to login!

    For the rest of my passwords I use my selfhosted vaultwarden

  • @MooCowGalaxy said:

    @jmaxwell said:

    That won’t make it hack proof anyway

    Well nothing is hack proof ;) Just needs an exploit, social engineering or lots and lots of time

    Agreed

  • @jmaxwell said:

    @MMzF said:
    And another sad news :(

    What seems to be that ?

    I got call from repair shop, and was told my laptop parts were not possible to arrange because of being too old parts are not available in market or the warehouse (junk parts) and is marked as no fix. :cry:

  • @froz said:

    Interesting. I'm on windows and use KeePass (Password Manager)+ Keeagent plugin + Putty to SSH. It's really fast to login!

    For the rest of my passwords I use my selfhosted vaultwarden

    I tried using self hosted vaults but the accessibility and ease of use for solutions like Termius or 1Password is just hard to beat :)

  • frozfroz Member
    edited November 2022

    1password is a solid product. just wish they had custom urls to filter the passwords that show up for my subdomains. they just do it on based on base url T.T. Meaning 10+ passwords show up for my one subdomain out of 10 for example.

  • @MMzF said:

    @jmaxwell said:

    @MMzF said:
    And another sad news :(

    What seems to be that ?

    I got call from repair shop, and was told my laptop parts were not possible to arrange because of being too old parts are not available in market or the warehouse (junk parts) and is marked as no fix. :cry:

    Well that’s sad

  • @froz said:
    1password is a solid product. just wish they had custom urls to filter the passwords that show up for my subdomains. they just do it on based on base url T.T

    Yeah, it's a bit annoying but I don't really mind, just need to add the subdomain once and leave it

  • @froz said:

    @MooCowGalaxy said:

    @sonu said:

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

    I use termius, like 1password but for SSH. Everything is encrypted and you need the master password to decrypt it, so I trust them.
    Also their pro plan is free with github student pack so :)

    Interesting. I'm on windows and use KeePass (Password Manager)+ Keeagent plugin + Putty to SSH. It's really fast to login!

    For the rest of my passwords I use my selfhosted vaultwarden

    Does vaultwarden have anything like keeagent out of the box?

  • frozfroz Member
    edited November 2022

    w/ bitwarden you can choose the URI detection method https://i.imgur.com/li5hjx4.png

    edit: bitwarden da original open source one. vaultwarden also open source = lighter weight implementation

  • @jmaxwell said:

    @froz said:

    @MooCowGalaxy said:

    @sonu said:

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

    I use termius, like 1password but for SSH. Everything is encrypted and you need the master password to decrypt it, so I trust them.
    Also their pro plan is free with github student pack so :)

    Interesting. I'm on windows and use KeePass (Password Manager)+ Keeagent plugin + Putty to SSH. It's really fast to login!

    For the rest of my passwords I use my selfhosted vaultwarden

    Does vaultwarden have anything like keeagent out of the box?

    not that i know of :[ will have to do DD

  • @MooCowGalaxy said:

    @sonu said:

    Then what can you do if you want to login from a different device?

    Put all the keys in authed keys?

    I use termius, like 1password but for SSH. Everything is encrypted and you need the master password to decrypt it, so I trust them.
    Also their pro plan is free with github student pack so :)

    You trust the termus

    That's the key point.

    How can you be sure they are safe?

  • B-L-A-C-K-F-R-I-D-A-Y

  • @sonu said:

    You trust the termus

    That's the key point.

    How can you be sure they are safe?

    Everything is end to end encrypted, the keys are only decrypted client side. I tested this with a network sniffer once, and indeed the only data that was being sent was encrypted

    Thanked by 1froz
  • @atroxz said:
    B-L-A-C-K-F-R-I-D-A-Y

    I-S-O-V-E-R

  • @jmaxwell said:

    @MMzF said:

    @jmaxwell said:

    @MMzF said:
    And another sad news :(

    What seems to be that ?

    I got call from repair shop, and was told my laptop parts were not possible to arrange because of being too old parts are not available in market or the warehouse (junk parts) and is marked as no fix. :cry:

    Well that’s sad

    Yea :/ that made me inactive and not possible to remain in this party...

  • I was looking in 1Password settings to see if they had any option for wildcard domains and came across this:
    https://developer.1password.com/docs/ssh/agent/
    Basically does what Termius does for me, although they don't have a built-in SSH client for mobile which I need.

  • @MooCowGalaxy said:

    @sonu said:

    You trust the termus

    That's the key point.

    How can you be sure they are safe?

    Everything is end to end encrypted, the keys are only decrypted client side. I tested this with a network sniffer once, and indeed the only data that was being sent was encrypted

    Sounds promising, but I still don't want to use a third party software.

    I monitor the login history and workloads, got hacked once.

  • If you're running your own servers, you could easily run Bitwarden/Vaultwarden. I've Vaultwarden installed on a free Google Cloud instance

  • @sonu said:

    Sounds promising, but I still don't want to use a third party software.

    I monitor the login history and workloads, got hacked once.

    Oof, do you know how you got hacked?

  • @MooCowGalaxy said:

    @sonu said:

    Sounds promising, but I still don't want to use a third party software.

    I monitor the login history and workloads, got hacked once.

    Oof, do you know how you got hacked?

    It was a free Oracle server, with default username 'ubuntu', default port 22, and a simple password, so I'm not worried about others.

This discussion has been closed.