Why do you think I'm missing that? Was it the part where I said that you should go ahead and obscure things in situations where you need every advantage you can get? (i.e. where I explicitly acknowledged that)
It costs something to use a port knocker. It costs something to use a nonstandard port. If you have strong authentication (say, using 2048-bit ssh certificates), it's probably not worth paying those costs. Maybe it is if you're a bank, but probably not if it's the server that hosts your blog. If you don't have that strength of authentication, it would be better to pay for the better authentication than for the port knocker and nonstandard port.
Comments
Why do you think I'm missing that? Was it the part where I said that you should go ahead and obscure things in situations where you need every advantage you can get? (i.e. where I explicitly acknowledged that)
It costs something to use a port knocker. It costs something to use a nonstandard port. If you have strong authentication (say, using 2048-bit ssh certificates), it's probably not worth paying those costs. Maybe it is if you're a bank, but probably not if it's the server that hosts your blog. If you don't have that strength of authentication, it would be better to pay for the better authentication than for the port knocker and nonstandard port.