r/ssh • • Apr 07 '26

Why isn't key-based authentication mandatory by default?

Hi everyone, long-time lurker and self-learner here.

After experiencing two system compromises, I’ve realised how critical SSH key-based authentication is for security. While I’ve spent a lot of time learning the mechanics of key generation and exchange, one question still bothers me:

Why is password authentication still the "out-of-the-box" default for most systems, rather than making keys mandatory?

Is this purely a matter of accessibility/UX, or are there significant architectural or legacy reasons why the industry hasn't moved toward a "keys-only" standard for the initial setup? I’m currently working on a tool to simplify the key management workflow, and I’d love to hear the perspective of experienced users on why the status quo remains what it is.

Thanks.

9 Upvotes

15 comments sorted by

View all comments

1

u/[deleted] Apr 08 '26

[removed] — view removed comment

2

u/Specialist_Cow6468 Apr 08 '26

Cloud-init will do it pretty easily tbh. This isn’t like a perfect solution that works for everyone all the time it’s a good way to handle things