3 ms·
I agree port knocking is a direct violation of Kerckhoff's principle. However, the proposed solution has non-discoverability from unauthorized sources which isn
by mvkg 2mo ago
I agree port knocking is a direct violation of Kerckhoff's principle. However, the proposed solution has non-discoverability from unauthorized sources which isn't necessarily in the threat model of OpenSSH or general cryptography. I do feel like this is potentially a desirable trait. I elaborated a bit more here[0], but I'm curious if you have any grander thoughts on how this could be approached
[0]: https://news.ycombinator.com/item?id=49307986 https://news.ycombinator.com/item?id=49307986
- yjftsjthsd-h 2mo agoIf you want that, I'd personally suggest wireguard. Bind sshd to the wg interface and it'll be invisible.
- teddyh 2mo agoNon-discoverability is useless. If you want remote logins with encryption and don’t trust OpenSSH, just use telnet and restrict its access to only IPsec-encrypted packets.