Urgent.News

What's breaking now, across thousands of outlets.

Tech

Restrict SSH Logins with AllowUsers Without Locking Yourself Out

A valid SSH key or password does not guarantee that an account can log in. OpenSSH can apply an additional server-side filter: AllowUsers lists which accounts are eligible to connect. That makes it useful for limiting remote access on a shared server—but a typo or incomplete list can lock out administrators and automation. Treat it as an access-control change, not just a line to add to a config…

AllowUsers is an OpenSSH server setting that filters which accounts are permitted to log in via SSH. It should be added to the server configuration file, not the client-side config. To limit remote access to specific users, list their login names after AllowUsers. For example, AllowUsers deploy would only allow the "deploy" account to connect.

Multiple users can be allowed by separating their names with spaces: AllowUsers deploy admin monitoring. These names must match the actual login usernames on the server. Adding AllowUsers does not create accounts or grant them shell access. It only serves as an additional access control, so listed users still need to satisfy the server's authentication and account policies.

Once an AllowUsers list is active, accounts not matching it will be excluded from SSH login, regardless of valid credentials. To prevent locking out administrators and automation accounts, carefully consider all people, deployment processes, and recovery logins that need access.

Access can also be restricted by source address. For instance, AllowUsers deploy@192.0.2.10 limits the "deploy" account to connections originating from the IP address 192.0.2.10. CIDR address patterns like AllowUsers deploy@192.0.2.0/24 can restrict connections to a specific network segment.

After adding restrictions, test from the intended network to ensure the pattern matches. AllowUsers can be combined with other directives like AllowGroups and DenyUsers, but Deny rules take precedence. Before applying changes, test the configuration with sudo sshd -t. Once verified, reload the SSH service and test fresh connections for each allowed account and source network.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Gas Optimization Audit: Poloniex

Gas Optimization Audit: Poloniex Target Protocol : Poloniex (TVL: $1648.2M) Poloniex – Gas‑Optimization Audit Prepared by: Senior DeFi Security Researcher – [Your Name] Date: 11 Oct 2026 1.

  • Poloniex commissioned gas optimization audit of on-chain components.
  • Audit found 28 gas inefficiency patterns, causing 12% higher transaction costs.
  • Implementing top fixes could save $1.2 million per quarter.

"Sign in with Google": Why It Bounces You Out and Back

You click "Sign in with Google." The page jumps away, jumps back a second later, and you are in. So why the round trip — why not just type something on this page?

  • Clicking "Sign in with Google" redirects to Google's approval page
  • Passcode grants temporary access to Google account without sharing password
  • Users can revoke app access anytime via "authorized apps"

The Celebrity Problem: From Brute Force to O(n)

Imagine you walk into a party with a few hundred guests. You don't know who anyone is, but you're told that one person there might be a celebrity .

  • Celebrity satisfies two rules: known by everyone, knows no one
  • Brute force approach has O(n²) time complexity, constant space
  • Efficient algorithm reduces time complexity to O(n) with O(n) space

Characterize Ship Cutoffs With Twelve Frozen Instants

Move one holiday check only after a frozen cutoff table holds. A messy ship function hides three clocks in one return. An early extract can flip a same-day answer without a failing test.

  • Function canshiptoday determines shipment feasibility
  • Cutoff time varies by carrier and VIP status
  • Shipment cannot be made on holidays or after cutoff

More from Sunday 11 October →