You are not logged in.
I just stumbled across this: Single packet authorization with fwknop
It sounds nice, I'm thinking of implementing it. What do guys think, have you tried it?
Offline
Port knocking has been around for a while. I don't see the point personally -- if you properly secure SSH in the first place, then there's no problem. I've got ~12 servers with SSH open to the world, and at work we have ~160 servers with SSH open to world. Never had an intrusion.
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
I've played with regular port knocking in the past and had no problem with that. Not worked with SPA specifically, but SPA is just a variant on that, with the crypto making it safer against replay attacks. Extra layers might make you safer at the cost of convenience. If using SPA, you would need a client to do the crypto knock first before ssh-ing in. So you would want to keep something with you that could do that if you ever had the urge to ssh.
It would add a layer on top of ssh's own security. Of course, the question is how safe is safe enough? IMO, unless you think you are going to be the specific target of an attacker (ie. running a bank's servers or something high-profile), there's not a whole lot of need. Most random probes on your system would just be script kiddies looking around the whole net for an easy target, not targeting you specifically. and as fukawi2 said, properly securing SSH itself does provide a great deal of security, especially if you used something like key authentication. But yes it will provide an extra layer and that might help you sleep better at night or something.
So is it fine to use and provide extra security layer? yes, it does that easily. Is it critical that you implement it? I doubt it. It's really up to you - there is no wrong choice here.
Nai haryuvalyë melwa rë
Offline