A correct sshd_config includes:
PasswordAuthentication no PasswordAuthentication no sudo apt install tinyssh
wget https://github.com/yourusername.keys -O ~/.ssh/authorized_keys
sudo systemctl enable tinysshd.socket
but it's not widely used, which makes using it risky. To my knowledge there hasn't been a formal audit. Also it doesn't implement the scp protocol, but you can use rscync over ssh alias scp="rsync -e ssh --progress"From the FAQ[1]:
> TinySSH doesn’t have problem with scp protocol, only doesn’t have scp program.
I assume this means an OpenSSH `scp` command will work just fine when pointed at a tinyssh daemon, without the rsync alias.
Immediate pro: Public domain / CC0
Immediate potential-con: Doesn't implement compression
ChallengeResponseAuthentication noThough, if you're using TOTP via a PAM module, you'll want it
openssh (1:4.1p1-1) experimental; urgency=low
[…]
* Disable ChallengeResponseAuthentication in new installations, returning
to PasswordAuthentication by default, since it now supports PAM and
apparently works better with a non-threaded sshd (closes: #247521).
[…]
-- Colin Watson <cjwatson@debian.org> Tue, 31 May 2005 01:33:33 +0100
https://bugs.debian.org/247521