3 ms·
From a purely technical point of view, I agree that it's more secure. But from a psychological point of view, isn't this system somewhat similar to security thr
by corentin 19y ago
From a purely technical point of view, I agree that it's more secure.
But from a psychological point of view, isn't this system somewhat similar to security through obscurity? That is, isn't it an incentive to not care about the rest (keeping the software up to date, monitoring the logs, etc.) because you now think that your SSH server is in a safe place, out of reach? Because, now, you may tend to think that nobody will seriously attack it (whereas you just filtered out the harmless, mass-scanning attackers).
I know you wrote "Of course, this doesn't replace making sure that the SSH server is up to date [...]" at the end of the article; but, well, most programmers will also tell you "you must document and test your software, brush your teeth three times a day, etc." :)
- jgrahamc 19y agoI share the concern about security through obscurity. But this isn't intended to be obscure (it's not like I change the port to 12222 and hope no one finds it). It's a technique like port knocking which relies on the algorithm being totally open but the underlying hash being unpredictable. All the security here comes from the passphrase + hashing combination which is designed to make the actual port difficult to determine. John