Sharing your SSH / FTP access with tech guys or other owner / admin?

Status
Not open for further replies.

Floris

I'm just me :) Hi.
Staff member
Jan 1, 2001
60,101
1,425
930
47
Netherlands
mrfloris.com
If you hire a tech guy, or have a shared owner, or have additional admins. You trust them right? Otherwise they wouldn't be in that position. Would you trust them enough to get shell or ftp access (or whm, cpanel, whatever)?

They can help manage the backups or fix bugs, etc.. But even if you trust them, would you give them access to your account with ftp and even ssh shell, or keep that to yourself?

One solution I have come up with is 24 hour rolling back ups of the images directory. Which is an account, which the designer might have access to, preventing the guy or girl from accessing other directories on the server.

What do you do, how much access do you share, and how have you prevented abuse?
 

Mikey

:mikey:
Staff member
Jan 26, 2008
17,836
692
510
33
Disunited Queendom
mikeylicio.us
The user never gets access to my account, or an account with any sudo privileges, but they do get their own restricted account. All actions any user takes should be logged, regardless of whether you trust them or not. This sounds harsh but eh, all your sites are on this one server (if you're smart you have backups), and one wrong move by an inexperienced user or even a wrong move by an experienced user who isn't thinking opens you up to hackers and insecurities.

Run an old version of a software for a friend, etc, it all creates vulnerabilities malicious users can exploit.
 

Heretic121

OMG Member
Sep 24, 2010
446
25
90
35
In respect to remote access to my server: If I trust someone enough to give them an account, which is a feat in itself, then I don't hold back.
In respect of web based accounts: I'm not big into giving any elevated privileges to people unless I've known them for a /long/ time.
 

melbo

OMG Member
Dec 2, 2010
116
0
55
51
The only ones with access to SSH and SFTP access are my host. When it comes to server admin outside of my managed dedicated, it's just me.

There are some that I would trust because they are friends and wouldn't trash my server intentionally... it's just that they might trash my server by accident.
 

Jason_imported

OMG Member
Feb 20, 2011
1
0
120
35
My admins manage the community, technical side is all handled by me so I need no need for them to have greater access.

I've always been the one who has funded/started projects though, i'm sure if I went into a partnership and there was equal input/ownership i'd be happy to share everything.
 
  • Like
Reactions: 2 people

Ingenious

OMG Member
Oct 26, 2010
68
0
55
www.firework-review.org.uk
Bit late to this one, but I wanted to add I would not trust anyone with any form of access they could trash the site with, intentionally or not. Even then I'd create an additional access for them which granted the same rights but which I could remove afterwards.

Life has taught me, it's the ones you trust most who shaft you! :)
 

CurveGotti

OMG Member
Oct 6, 2010
264
0
75
904
I very rarely share login's for anything beyond the software on the site's administrative level, there is usually no need, and when there is I create a temp account and delete it once any task they are working on is complete.
 

CurveGotti

OMG Member
Oct 6, 2010
264
0
75
904
I'm try to avoid getting anything such as SSH information to make the client feel secure in hiring me.

I try and do the same thing when I am working on other sites, not only do I try to avoid needing access to certain things, but I explain why they should be more careful about offering such access when they do try and give me the passwords. I always tell them to only give it when someone specifically asks for it for a specific reason that they can confirm is a legitimate need.
 
  • Like
Reactions: 1 person

Medora_imported

OMG Member
Sep 12, 2011
14
0
55
36
I have several fellow administrators. Although I only shared FTP and phpMyadmin access with one of these administrators, it is not because I trust the others any less; rather, it has to do with circumstance.

For example, my forum started out on a free host before this fellow administrator offered to host it for me for free. And after it was moved to a paid host, he generously donated his time and effort to make the strenuous conversion of the forum from phpBB 2.x to vBulletin 3.x.

In short, he has done just as much (if not more) for the forum than me, and giving him complete access just naturally happened. As for the other administrators, they have never concerned themselves with the tech side of the forum; they are concerned only with the management within the forum itself rather than behind the scenes.
 
Status
Not open for further replies.