3 ms·
There is a flip side of that as well though. You may have a tool that tries to look at all SSH traffic across a fleet of servers (maybe trying to identify compr
by thinkharderdev 6y ago
There is a flip side of that as well though. You may have a tool that tries to look at all SSH traffic across a fleet of servers (maybe trying to identify compromised internal hosts). If every server has sshd running on a different random port then you can't do this (or at least it becomes a lot harder).
More generally, I think there is in fact a trade-off involved in deciding to explicitly ignore standards. Whether it hobbles automated network analysis or just causes friction in the development process, it can add up over time. That is not to say it is always a bad idea but I would just caution that, just as you shouldn't blindly reject "security by obscurity" you shouldn't blindly accept "security through obscurity" even if you have layered defenses. There is no substitute for thinking about individual circumstances and weighing explicit trade-offs.
- staticassertion 6y agoNo question, it's not a 0 cost change.