5 ms·
I recognize that this is a joke, in the words of the OP. However I think SPA-type port knocking is completely legitimate, and I second the use of fwknopd. I d
by georgeam 10y ago
I recognize that this is a joke, in the words of the OP. However I think SPA-type port knocking is completely legitimate, and I second the use of fwknopd. I depend on fwknopd a lot, so if that is not secure idea, I would like someone to point that out to me. NOTE that fwknopd does not depend on expecting a client to connect to a short sequence of different port numbers. That is not what fwknopd does, at least not the latest fwknopd. Instead, fwknopd listens for an encrypted packet on a specified port, which it will not acknowledge. The firewall does not allow the packet through, technically speaking. But fwknopd recognizes the arrival of the packet by scanning logs when the firewall drops the packet and logs the dropped packet. etc. etc. If you know this type of fwknopd deployment and don't think it is a good idea, please comment.
Again, I am not taking the OP seriously, but I do take seriously that people either don't know about fwknopd, or maybe, don't think that is good security (in which case I want to hear from you).
- belorn 10y agoCorrect me if I am wrong here, but would the following changes to SSH give you the same result: Change protocol from TCP to UPD and port from 22 to 62201. Remove greeting. If first message is not the correct password, do not send a reply. If everyone used this, do you think SSH would become more secure and eliminate password scanners? Personally I think that if ssh took in a fwknopd patch and used that as default, any benefit you see now would disappear. I also suspect that logging every UDP package to 62201 would be a bad idea, probably worse than logging every failed attempt on TCP port 22.
- oneru 10y agoSsh does a fingerprint verification and establishes a secure channel before it does the password exchange. Avoiding replay attacks can be a challeng as well. Putting strong authentication in a single packet is deceptively nontrivial. It can be done, but at that point you'd be reimplementing Fwknopd. Additionally, Fwknop can protect more than just ssh, and do fancy things like providing access to a machine without a public IP address. Disclaimer: I'm one of the Fwknop devs. =)