http://treasurechest.i2p/setup.html
This way, my access-control policies only need to allow specific executables, rather than a whole language interpreter which would, if exploited, give an attacker ample control of the machine. SFTP For its maturity, configurability, and security, I run the usual OpenSSH server, although I'm not entirely happy with its security track record. Only the adventurer user is allowed, with an empty password, and only to run SFTP sessions - no shell, obviously.