Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I decided to enable port knocking. So SSH is not available on any port, without right kind of packets being sent beforehand.


Security through obscurity.


Obscurity is fine as a layer in your security strategy.


With Moxie Marlinspike's KnockKnock[1] port knocking offers real additional security.

1) http://www.thoughtcrime.org/software/knockknock/


Yes, much like choosing an obscure sequence of bits to function as one half of a public/private keypair during an SSH protocol handshake.


Not quite.


Port Knocking packets can have strong crypto payload. So yes, it's not really any different than using VPN. (Yes it is technically yes, but it allows you to open access from one IP address, using strong authentication for service, which still got strong authenticaiton. TOTP, private key and password.) It's just front blocking access to that tcp port without the right opening packet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: