4 ms·
I personally don't use Single Packet Authentication, for exactly the reasons you cite here, but I can understand some of the motivations. The use case that fee
by tene 12y ago
I personally don't use Single Packet Authentication, for exactly the reasons you cite here, but I can understand some of the motivations. The use case that feels convincing to people that do use it, from what I've been able to understand, is that it does protect them somewhat from misconfiguring OpenSSH. If you fuck up and leave password auth enabled and a password set, and you fuck up and don't have monitoring on failed authentication and something like fail2ban or denyhosts, then fwknop is yet another thing that you'd have to fuck up before you're wide open to the brute-force crawlers. One solution to this is "just don't fuck up", but I can understand people having different levels of paranoia about this. Sure, it also protects you from bugs in OpenSSH, but misconfiguration is WAY more likely for your average OpenSSH installation.