More locks for your SSH door. My first article about hardening SSH access (see Resources) considered three methods that are suitable for small operations, such as a home server or a small business with few people requiring remote SSH access: Changing SSH's standard port to an unusual value and reinforcing SSH configuration so that simple-minded attacks just bounce back.Defining a restricted list of users who are allowed to log in using Pluggable Authentication Modules (PAM).Completely hiding the fact that you even allow SSH access and requiring a special "knock" sequence to be recognized as a possible user.

Using PAM to define a restricted list of users who are allowed to log in still makes sense for larger setups, but the other two options can become bothersome. Therefore, this article examines a couple methods of enhancing security that you can more easily apply to larger configurations:



It’s as if someone took one of those composite satellite maps - you know, impossibly showing the whole world at night, the darkness broken by hubs and strings of artificial light (1) - and gave it the power of speech. For the riot of colours on these maps correspond to the diversity of languages spoken, or rather: typed, on Twitter. The explosive growth of the micro-blogging service’s global popularity is emblematic of a trend affecting the entire internet: it’s becoming less American, and less Anglophone.

