> is it very naive of me to assume that turning off passwords and only 
> allowing key based auth is a valid way of dealing with people attempting 
> to brute force their way in?

no, but it will protect you from an exploit ?

