Comment by doorsopen

Comment by doorsopen 12 hours ago

1 reply

As someone who works with SREs every day, this breaks my heart.

1 - Don't be on-call while going to ski

2 - fail2ban and other automated systems can do this for you

3 - Passwords suck and are typically not regularly rotated unless you're using some centralized IdP

If you're in this situation you have already failed. If you use password auth use 2FA as well, and then I don't cry, it's just toil though.

sam_lowry_ 10 hours ago

1. It breaks my heart to see indie dev spirit die even on HN.

2. it's brittle and too automated to my taste. There may be false positives that I'd fait to review if it was too automated.

3. There should be a very limited set of passwords for your main assets. For instance, one for infrastructure, one for a password manager, one for the safe at home. And they should never be rotated. They are meant to be ingrained in muscle memory and stay with you for many years.