Hacker News new | ask | show | jobs
by gosub100 567 days ago
If a network intrusion detector warns about something being changed, you can review the logins to see that it happened right as an authorized person accessed the box. A common practice is to not allow root direct ssh access.