| ▲ | pdpi 3 hours ago | |||||||
Port knocking isn't security through obscurity. Given the knowledge that you have a port knocking system in place doesn't tell me what specific sequence of knocks will open up the service I want to target. Even just a two knock sequence gives you a key with 32 bits of entropy, which makes it trivial to block attempts at bruteforcing the key. | ||||||||
| ▲ | ZoomZoomZoom 2 hours ago | parent [-] | |||||||
I don't see how your argument makes sense. It's all just bits of entropy in the end, be it knowing a port to connect to or a character in your key. | ||||||||
| ||||||||