Hacker News new | ask | show | jobs
by Sebb767 1660 days ago
Adding to that, some servers might have a secondary user with a weak password that was created by an installer or an admin for testing purposes. Disallowing password login prevents others from exploiting these accounts.
1 comments

Agreed, that's why I put "If you are running a server where only you SSH in" but maybe I should have been more clear about it.