One reason that this is so serious, is that by implying during the installation that an SSH server will not be installed, users won't necessarily choose secure passwords for their user accounts.

The SSH server that is installed will allow access to anyone who has a valid username and password for the machine. If a user, thinking that there are no servers running on the machine, chooses a password of 'password', 'asdf' or 'bob', or some other unsecure password, they will almost certainly be hacked. Having such a weak account when there's a server running on port 22 is just asking for trouble.

Reply via email to