Skip to content

Comment on Three locks for your SSH doorparent

Comments

Why do you think I'm missing that? Was it the part where I said that you should go ahead and obscure things in situations where you need every advantage you can get? (i.e. where I explicitly acknowledged that)

It costs something to use a port knocker. It costs something to use a nonstandard port. If you have strong authentication (say, using 2048-bit ssh certificates), it's probably not worth paying those costs. Maybe it is if you're a bank, but probably not if it's the server that hosts your blog. If you don't have that strength of authentication, it would be better to pay for the better authentication than for the port knocker and nonstandard port.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.