So a DO/Rackspace/AWS VPS with a guessable root password can expect to be cracked in ~4 hours? That's terrible! AFAIK, AWS defaults to ssh-key logins with password logins disabled. Can someone comment about Rackspace/DO?
1) Password authentication 2) Root authentication 3) Changed root password to "password"
All the providers offer fairly safe defaults, either using very random passwords or just enabling SSH keys.