Earlier quoted context omitted.
Devil's advocate. As someone who has developed a Linux based appliance with over 100k live units across the globe, it seems insane to NOT have access to the thing you're selling and that you have to maintain. If your thing breaks or gets bricked by an update, you will call support and expect them to fix it. You don't want to send in your device or have a support technician come to your house to fix it. So yes, to the…
And I'm sure every one of those 100k devices has a unique ssh key right? Surely you can see the problem.
- per session ssh keys that are valid for only 6 hours
- all ssh sessions are audit logged and have to go through jump servers tied to tech roles
- all sessions fully monitored via "script" and can be replayed
You can also see a write-up here: https://news.ycombinator.com/item?id=40840040