TIP: Click on subject to list as thread! ANSI
echo: rberrypi
to: ALISTER
from: BIG BAD BOB
date: 2017-10-23 01:05:00
subject: Re: RVNC.

On 09/25/17 02:20, alister wrote:
> On Sun, 24 Sep 2017 13:16:00 +1200, Henri Derksen wrote:
>
>> Hello Nikolaj,
>>
>>>> I think I may just use the software RealVNC.  I have used this in the
>>>> past with windows.  I'm trying to get a toe-hold with some of the
>>>> things I know and expand from there.
>>
>>> Tunnel it through ssh for extra protection if you plan to put your
>>> machine on the Internet.
>>
>> Be aware to change the "default is your fault" password for user Pi
>> immediately before connecting your Pi's to InterNet !
>> Because default SSH is set ON and anybody can login with the default
>> password witch has ROOT capabilities!
>> Change it to something cryptic,
>> with at least one capital and one number and/or special character in it.
>> Good luck with it.
>> Greetings from Henri, a Raspbian Linux and RISC OS Pi 3B user.
>
> even better reconfigure ssh to require secure key authentication
>
> it does not take much more effort than changing the password (which is
> still strongly recommended)
>
>
>

ideally, only enable ssh for specific users, then require them to 'su -
pi' to access sudo.  with a cryptic password on BOTH of them.  And ONLY
cryptic "non-dictionary-guessable" user names that can ssh in.

and never... EVAR... allow root to ssh in directly.  ALWAYS require an
'su' or use of 'sudo' (with a password) for root-level access.  The
convenience setup would allow you to 'sudo su' to get a "root console"
whenever you need it, so there ya go.

--- SoupGate-Win32 v1.05
* Origin: Agency HUB, Dunedin - New Zealand | FidoUsenet Gateway (3:770/3)

SOURCE: echomail via QWK@docsplace.org

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.