3
I have a question regarding SFTP and security. Is using SFTP without keys, still more secure (eg. encrypted) than plain FTP?
3
I have a question regarding SFTP and security. Is using SFTP without keys, still more secure (eg. encrypted) than plain FTP?
2
Yes, it's still encrypted and therefore much more secure. Just make sure to use a strong password, and it's best to use a non-standard port or you'll have bots constantly hitting your server trying to guess the password.
1
Yes. Private/public key authentication just generally make the encryption stronger as the keys are usually way longer (1024-2048 bits) and a way more random than a typical password.
Also with keys you can:
0
It depends.
With SFTP traffic is encrypted, so in that sense it is more secure than plain FTP.
On the other hand, SFTP is just a subsystem of SSH. You have to configure SSH carefully in order to restrict people accessing the server to a chroot environment and disallow shell and SCP access. That's usually granted by default for most FTP servers.