Report this

What is the reason for this report?

Prevent root password from being sent over email?

Posted on October 12, 2012

Your website states in a few places that when you create a server, the root password is sent over email so that you can log in as root. This is a terrible security practice: email is hideously insecure, and it’s generally a bad idea to permit password-based logins for root. Is it possible to set up ssh key access before you provision a droplet, so that when the server starts it has either OpenSSH or Dropbear running, with the public key loaded, and password-based logins for root disabled? Or at the very least, to not send the root password via email?

The developer cloud

Scale up as you grow — whether you're running one virtual machine or ten thousand.

Start building today

From GPU-powered inference and Kubernetes to managed databases and storage, get everything you need to build, scale, and deploy intelligent applications.