<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: L2hhdGNoZXQv</title><link>https://news.ycombinator.com/user?id=L2hhdGNoZXQv</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 07 Oct 2026 11:04:47 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=L2hhdGNoZXQv" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by L2hhdGNoZXQv in "Most of what you read on the internet is written by insane people (2018)"]]></title><description><![CDATA[
<p>Upvoting, maybe.</p>
]]></description><pubDate>Fri, 01 Jan 2021 18:03:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=25605140</link><dc:creator>L2hhdGNoZXQv</dc:creator><comments>https://news.ycombinator.com/item?id=25605140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25605140</guid></item><item><title><![CDATA[New comment by L2hhdGNoZXQv in "Linux Hardening Guide"]]></title><description><![CDATA[
<p>> If you access many machines, how will you know when one is compromised? How will you prevent an attacker from logging in as you?<p>Even better is to use SSH certificates. That way you don't have to deal with authorized (usually permanent) keys.<p>Once the SSH CA is installed in the host, the client can generate temporary asymmetric keys and sign them with the CA key before every connection.<p>There are a few ways to set up this scenario, here's one using Vault:<p><a href="https://www.vaultproject.io/docs/secrets/ssh/signed-ssh-certificates.html" rel="nofollow">https://www.vaultproject.io/docs/secrets/ssh/signed-ssh-cert...</a></p>
]]></description><pubDate>Thu, 31 Dec 2020 15:09:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=25593314</link><dc:creator>L2hhdGNoZXQv</dc:creator><comments>https://news.ycombinator.com/item?id=25593314</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25593314</guid></item></channel></rss>