Not to mention that modern-day IT systems are such a mess that you'd need a crazy amount if time to find and access them all.
1,557 karma · joined April 20, 2022
Not to mention that modern-day IT systems are such a mess that you'd need a crazy amount if time to find and access them all.
Things that could be done is making password auth harder to configure to encourage key use instead, or invest time into making SSH CAs less of a pain to use. (See the linked paper, it's not a long read.)
From my experiments with several honeypots over a longer period of time, most of these attacks are dumb dictionary attacks. Unless you are using default everything (user, port, password), these attacks don't represent a significant threat and more targeted attacks won't be caught by this. (Please use SSH keys.)
I have seen experienced sysadmins create the test user with the password of "test" on a live server on port 22 because they were having an "autopilot moment". It got hacked within 20 minutes of going online and these mechanisms wouldn't have saved it, the attacker got in on the second or third try.
If you want to have a read about unsolved problems around SSH that should be addressed, Tatu Ylonen (the inventor of SSH) has written a paper about it in 2019: https://helda.helsinki.fi/server/api/core/bitstreams/471f0ff...
If you maintain a project, it may be cool to hear the big names using something you make for free, but consider what they are asking for and if you are putting yourself in potential legal liability by providing said compliance work. They have money to spend and if it's important enough, they will.