![](https://lemmy.world/pictrs/image/49d23c03-7459-4af8-941d-c89daa202e62.png)
![](https://lemmy.world/pictrs/image/4271bdc6-5114-4749-a5a9-afbc82a99c78.png)
15·
2 days agoAlthough disabling the root user is a good part of security, leaving it enabled should not alone cause you to get compromised. If it did, you were either running a very old version of OpenSSH with a known flaw, or, your chosen root password was very simple.
It should be a serious red flag that your VPS host is generating root passwords simple enough to get quickly hacked.