|
|
|
|
|
by akerl_
1744 days ago
|
|
As I said: changing the port is just a means to avoid having to `apt install logrotate` Active alerting on brute force attempts on an internet-facing SSH service is an exercise in human suffering. At best you don’t get any alerts, and at worst you get alerts that you do… what, precisely, with? Block the IP? Look up the “human” attacker and send them an email asking them to stop? There are environments and entities for whom pattern detection on incoming connections makes sense, and those environments aren’t running internet-facing SSH. |
|