logoalt Hacker News

mvkgtoday at 5:57 AM1 replyview on HN

I agree port knocking is a direct violation of Kerckhoff's principle. However, the proposed solution has non-discoverability from unauthorized sources which isn't necessarily in the threat model of OpenSSH or general cryptography. I do feel like this is potentially a desirable trait. I elaborated a bit more here[0], but I'm curious if you have any grander thoughts on how this could be approached

[0]: https://news.ycombinator.com/item?id=49307986


Replies

yjftsjthsd-htoday at 7:22 AM

If you want that, I'd personally suggest wireguard. Bind sshd to the wg interface and it'll be invisible.