4 ms·
Yes, an AES-CTR transformation would be more secure than any port knocking variety such as SPA, at the cost of being more complicated. But the point in port kno
by arde 12y ago
Yes, an AES-CTR transformation would be more secure than any port knocking variety such as SPA, at the cost of being more complicated. But the point in port knocking is not its intrinsic security, which is not worth to talk about: its point is actually the obscurity it adds to some other secure access method such as SSH, and its ease of implementation and usage. With it you get much shorter and less noisy logs to monitor, and it's almost for free. In a way, it can be compared to camouflage: its dirt cheap and quite effective at avoiding hits. Bulletproof vests or armoring are still required, but the question is why would you NOT be camouflaged when you can?
- tptacek 12y agoYou're not thinking the threat model through. If you're not concerned about the kinds of serious, dedicated attackers who have OpenSSH zero-day, you're fine leaving properly-configured OpenSSH exposed. If you are concerned about those attackers, port knocking is barely a speed bump. I also dispute that a plugboard proxy is "more complicated" than "cryptographic port knocking".
- arde 12y agoI agree with what you say regarding the APT scenario, port knocking is mostly useless there. It wouldn't be an effective camouflage in that case, and one probably has bigger problems than a hypothetical OpenSSH zero-day then. I'm not aware of any available plugboard proxy solution, so it would have the added complication of hacking it together. That's what I meant. And there are diminishing returns there: a non-criptographic port knocking scheme with a few packets could be good enough as a camouflage in many cases. But I still find it to be a time saver in the more general case (not APT). I think having cleaner logs is worth using this simple trick then.
- philsnow 12y ago> If you are concerned about those attackers, port knocking is barely a speed bump. is this because you expect this class of attackers to be able to thwart port knocking more or less trivially ?