• 0 Posts
  • 2 Comments
Joined 3 years ago
cake
Cake day: June 19th, 2023

help-circle

  • For many places, it’s operational inertia. If you’ve had a hosting account at the same place since 1998, you’re bound to still have username/password access to services like FTP even though other (and better) options exist.

    And then there is the issue of sole control. Many greybeards like myself still run traditional username/password auth on services because,

    1. We have whitelisted our IP address, and if dynamic, keep that whitelist updated
    2. That outside of said whitelisting, the service is a quasi-honeypot meant to protect the machine as a whole. Any connection made from outside the address space of my ISP, by anyone else, is by default considered malicious, and is banned instantly as a precaution. They don’t even get the opportunity to attempt a login; merely connecting to said service is sufficient evidence of hostile intent.

    So while my setup is not ideal, it is ideal for myself. if I had anyone else as co-admin, or even clients, things would get stupidly complicated very quickly. But since it’s just me…