• Latest
  • Trending
  • All
Answer card: a sudo user instead of root, SSH keys with passwords off, a default-deny ufw firewall, fail2ban, and automatic updates. Set up the key before disabling passwords.

How to secure a new Ubuntu VPS

3 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
Answer card stating that OpenAI published its research acceleration measurements on 6 September 2026, that as of mid August 2026 its research organisation logged 3.1 agent workdays of coding agent runtime for every workday of human labour normalised to a standard eight hour day, and that OpenAI states this should not be read as a 3.1 times productivity gain because it measures runtime rather than delivered output.

OpenAI’s 3.1 agent-workdays per human day is not a 3.1x gain

7 September 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Friday, September 18, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

How to secure a new Ubuntu VPS

by stephane
3 September 2026
in Security
0
Answer card: a sudo user instead of root, SSH keys with passwords off, a default-deny ufw firewall, fail2ban, and automatic updates. Set up the key before disabling passwords.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Spin up a fresh VPS and check the auth log an hour later. It's already full of bots hammering SSH, which is why we lock a new box down before deploying anything, and it's five moves: a normal sudo user instead of root, SSH keys with passwords off, a default-deny ufw firewall opening only the ports we actually serve, fail2ban for the brute-force noise, and automatic security updates. Ten minutes of work, give or take. The one rule that saves your afternoon: set the key up and test it before you disable passwords, or you'll lock yourself out of your own machine.

The short answer

A sudo user instead of root, SSH keys with passwords off, a default-deny ufw firewall in front, fail2ban, and automatic security updates. Set up and test the key before you disable passwords. That’s the whole trick.

keys onlypasswords off in sshd_config
deny by defaultufw, open only what you serve
fail2banbans the brute-force noise
Answer card listing the five steps to harden a new Ubuntu VPS, with the warning to set up the key before disabling passwords.
Five steps, in this order. The order is the part people get wrong.

A user, keys, and no more root login

Every bot on the internet tries root first. It’s also the account where a typo has no safety net, so we make a normal user with sudo and work from that instead:

Linux
adduser deploy
Linux
usermod -aG sudo deploy

Log back in as deploy and check that sudo whoami returns root. From here on, root is something we reach through sudo, not a door left open.

A password can be guessed. A key can’t, not in any timeframe that matters. If you don’t have one yet, our guide to ssh-keygen covers it. Copy your public key up to the new user:

Linux
ssh-copy-id deploy@your-server-ip

Now the careful part. Open sudo nano /etc/ssh/sshd_config, set PasswordAuthentication no and PermitRootLogin no, then reload SSH:

Linux
sudo systemctl reload ssh

Before you close anything, open a second terminal and confirm a key login works. That spare session is your seatbelt. Fat-fingered the config? You can still get back in and fix it.

A default-deny firewall, plus fail2ban

ufw makes this painless. We deny everything inbound, then open only the ports this box actually serves. Allow SSH first, before enabling, or you cut your own connection:

Linux
sudo ufw allow OpenSSH

Add 80 and 443 if it serves a site, then turn it on:

Linux
sudo ufw enable
Terminal showing ufw default deny incoming, allow OpenSSH, allow 80 and 443, enable, then ufw status listing the open ports.
Deny everything, open only what you serve, SSH first. Then check status.

Even with passwords off, the login attempts keep coming. They fill your logs. fail2ban watches them and bans an IP after a handful of failures, and on Ubuntu it protects SSH the moment it’s installed:

Linux
sudo apt install fail2ban

Want to tune the ban time or threshold? Copy the packaged defaults into /etc/fail2ban/jail.local and edit there, never the original. Honestly, for most boxes we don’t touch them.

Automatic updates, and why the order matters

Patches only help if they land, and nobody logs in every day to run them by hand. We certainly don’t. unattended-upgrades installs security updates on its own:

Linux
sudo apt install unattended-upgrades
Linux
sudo dpkg-reconfigure -plow unattended-upgrades

Answer yes when it asks. The box now patches itself against the vulnerabilities bots weaponise within days of disclosure.

None of these steps is hard on its own. People lose an afternoon by doing them out of order: passwords off before the key works, or the firewall on before SSH is allowed. Follow the order above and keep that second terminal open through the SSH change. About ten minutes, and a fresh VPS goes from wide open to quietly locked down.

The one rule that saves you from locking yourself out: never close the session you’re working in. Open a second terminal, log in as the new user with the key, and prove it works before you touch PasswordAuthentication or restart sshd from the first session. If something is wrong you still have a shell to fix it from.

Order matters for the firewall too. Allow SSH before you enable ufw, not after, because ufw enable takes effect immediately and a default-deny policy with no SSH rule ends your connection on the spot. The provider console is your only way back in at that point, and on some hosts that’s genuinely painful.

Ubuntu
sudo ufw allow OpenSSH && sudo ufw enable

If you moved sshd to a non standard port, allow that port by number instead. The OpenSSH profile only covers 22, and plenty of people have discovered that the hard way about four seconds after typing enable.

None of this is exotic, and that’s rather the point. A box that’s done these things isn’t secure in any absolute sense, but it’s stopped being the easy target that opportunistic scanning is looking for, and that’s most of the battle on a small server.

Frequently asked questions

Will I lock myself out doing this?

It's the real risk, and it's avoidable. Before you disable password login, open a second terminal and confirm a key login works. Keep that session open while you edit sshd_config and reload SSH; if something's wrong you still have a way back in. Only close it once a fresh key login works on its own.

Do I need to change the SSH port?

Optional, and mostly cosmetic. Moving SSH off 22 quiets your logs because most bots only probe the default, but that's obscurity, not protection. Keys with passwords disabled plus fail2ban do the actual work. Change the port if the calmer logs are worth it to you, not because you think it makes the box safe.

Is fail2ban still worth it if passwords are already off?

Less critical, sure, but it's cheap and we keep it on. With key-only SSH a brute force can't succeed anyway, so there fail2ban is mostly trimming log noise. It earns its keep guarding whatever else you expose later, and it costs almost nothing to run.

PermitRootLogin: should it be no or prohibit-password?

Use no once your sudo user works; root then can't log in over SSH at all. prohibit-password is the middle ground: root can still log in with a key but never a password, which some automation depends on. If nothing needs direct root SSH, no is the cleaner choice.

Tags: firewallguidesecuritysshubuntuvps
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.