I did a bunch of recommended stuff to make my server hard to access, so that only with a private ssh key could I get into it. But then I find that the linode website still allows easy password-only access to it.

Am I missing something?



2 Replies

So you chose to not turn on Two-Factor authentication on your account??

Login -> Profile -> Password & Authentication….

Enable Two-factor authentication

Enable Account security

You can also control Lish's allowed authentication modes in Profile -> Lish Settings.



