Oněch „20 zásad bezpečnosti“ jsou spíše poznámky možností OpenSSH, není to žádné dvacatero, například nastavovat idle timeout u stroje, kam se přihlašuji z osobních počítačů, je blbost. Nebo login jako root, to abych citoval:
Saying „don't login as root“ is horseshit. It stems from the days when people sniffed the first packets of sessions so logging in as yourself and su-ing decreased the chance an attacker would see the root pw, and decreast the chance you got spoofed as to your telnet host target, You'd get your password spoofed but not root's pw. Gimme a break. this is 2005 – We have ssh, used properly it's secure. used improperly none of this 1989 will make a damn bit of difference. -Bob

