On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • BrianTheeBiscuiteer@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    4 days ago

    Doesn’t even have to be the key necessarily. Could get in via some exploit first. Either way taking over the machine became a 2-step process.

    • ☂️-@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      3 days ago

      you would need 2 different exploits for 2 different types of attack though.

      its always good to have an extra layer of “oh shit i need another exploit”. unless your threat modelling includes nation-states, that is.