Actually, yes.
I thought I'd disabled password access on Vulture. So it must be ignoring the ssh key and allowing me in with password access only.
By the way - I don't understand what the big fuss is with security and masternodes.
So what if someone gets access to my masternode ?
It's no different from a "bad actor" just setting up their own masternode and doing whatever they want to do with it. What can they do anyway ?