4 ms·
They then have 30 seconds to find the port, which is feasible. So... combine TOTP with port knocking and make sshd unnecessarily difficult to find!
by btym 10y ago
They then have 30 seconds to find the port, which is feasible. So... combine TOTP with port knocking and make sshd unnecessarily difficult to find!
- est 10y ago+1 for port knocking. Should be used more.
- xenophonf 10y agoI don't get the love for port knocking. If you need such a thing, wouldn't a proper VPN implementation be more robust? Edited to add: I'm asking for a clue. Thanks in advance. :)
- est 10y ago> wouldn't a proper VPN implementation be more robust? Suddenly your whole VPN infrastructure became an attack surface.
- throwaway2048 10y agoI trust openssh a hell of a lot more than any vpn software.
- lmm 10y agoSure, but I also trust it a hell of a lot more than any port knocking implementation. If SSH is your point of trust... make it your point of trust. Throwing up an extra layer of obscurity on top doesn't help anything.
- geographomics 10y agoIf the port knocking was obscuring an unauthenticated root shell then you would have a good point, but this is a defence in depth measure that adds to the security. It helps because it's one more hurdle for an attacker to bypass.
- lmm 10y agoLayering two actual security measures makes sense. Layering an obscurity measure on a security measure is not really any safer than just having the security measure, just as obscurity alone is not really any safer than nothing.
- geographomics 10y agoIt is a security measure, as it involves authentication through the series of knocks. It's a weak security measure on its own, so you obviously wouldn't want to rely on port knocking by itself, but it does have utility in preventing an attacker from discovering the service through a simple port scan. I don't quite understand why you're saying it adds nothing at all.
- ethbro 10y agoIn essence, it's the same argument as "everyone should use encryption, even if it's barely non-trivial for state-level actors to break." You're not defending against the attacker who is targeting you with this. You're defending against the attacker who is targeting "anyone who is trivially accessible."
- knorker 10y agoNo. Port knocking is self-deceptive and stupid. It's a password. Sent in plain text. But because users pretend that it's stealthy they pretend that it's something else. Yes, you can have your port-knocking be an OTP. But why? Why not just listen to an UDP port that takes this plain text password or OTP like a sane person? Why sniff SYN packets? What exactly does port knocking add to this, except make it MUCH more probable that your raw-packet-sniffing-oh-so-coolness has a security hole than that your "open UDP socket, read packet, check for equality" has a security hole? With IPv6 TCPMD5 (or TCP AO) becomes a much more interesting way to solve this.
- rdslw 10y agoThere are quite a few arguments: * attacker can't do successfull bruteforce attemps at the same rate or at all * attacker can't reliable intercept (MITM) traffic, as he does not what port is being used * attacker can' launch sshd DoS attacks, as he does not know where does sshd listen at (at least he has to try 65000 x bigger space, this precludes a lot of time based attacks
- knorker 10y agoAre you talking about the "run sshd on a different port" or portknocking? I'm not sure how what you said is related to what I said.
- knorker 10y agoNo. Port knocking is self-deceptive and stupid. It's a password. Sent in plain text. But because users pretend that it's stealthy they pretend that it's something else. Yes, you can have your port-knocking be an OTP. But why? Why not just listen to an UDP port that takes this plain text password or OTP like a sane person? Why sniff SYN packets? What exactly does port knocking add to this, except make it MUCH more probable that your raw-packet-sniffing-oh-so-coolness has a security hole than that your "open UDP socket, read packet, check for equality" has a security hole? With IPv6 TCPMD5 (or TCP AO) becomes a much more interesting way to solve this.
- e40 10y agoPort knocking is all you need. We have had 0 attempts since starting to use it.