Author: momentaryblip
Channel: #feedback
Link: https://discord.com/channels/1405685085923049482/1405686161791516873/1460836398901756005
Issue
The exeuntu image currently has PasswordAuthentication yes enabled in the SSH daemon configuration. This should be changed to no unless there is a specific reason it needs to remain enabled.
While there is a proxy in front for SSH routing that acts as a security layer, it's still best practice to disable password authentication at the SSH daemon level.
Context
This appears to be an oversight in the sshd configuration. The assumption is that since you need to be on the machine to access it, password auth isn't strictly necessary.