frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

I close SSH port 22 (and what I use instead)

https://www.michelebologna.net/2026/ssh-port-22-fwknop-single-packet-authorization/
15•speckx•4d ago

Comments

mrktf•4d ago
I would go with something like:

  seed=`date +%s%N`; ( echo "secretknock-20260811|$seed"|sha512sum  ; echo $seed ) | xargs nc -u 192.168.1.1
It is not secure as hmac and it can be 'trivially' brute forced, but don't require extra tools (probably nc not always readily available).

On other hand if threat vector includes network monitor with ability to replay i would use wireguard to wrap ssh traffic.

jauntywundrkind•38m ago
Why not just use ssh as the knock protocol too? To a bespoke ssh server. Ssh to 7000, type "mellon", and ssh 22 opens up. No other software required, and you clearly already have ssh.
cynicalkane•21m ago
That's a good idea, but on the other hand, it seems inappropriate to use such lore in the manner of a lore-master in these suspicious days; not a fitting reference for the happier times of Durin.
fedpost•37m ago
Is this actually practically reducing the attack surface? We're replacing a battle hardened service with a random one that has the ability to manipulate the firewall rules.
simondotau•28m ago
A sensible observation. In theory, the entire codebase for a simple HMAC knock knock ought to be tiny and easy to harden with multiple rounds of human and LLM review.

The goal should be to have your complex layers sitting in front of simpler, easier-to-review lines of defence. Once you get to something like an open connection to ssh, the potential attack surface would be orders of magnitude larger, even though it’s more mature and closely scrutinised.

zsoltkacsandi•19m ago
If you mean fail2ban by “battle hardened service”, it manipulates the firewall rules as well. And OpenSSH has the same functionality built-in, without any additional service (PerSourcePenalties).
suprjami•33m ago
> and why it is not enough on its own

Nothing is good enough on its own.

Geoblocking, fail2ban, port obscurity, SSH keys, limiting logins to specific usernames, not using your public internet nickname, putting things behind CloudFlare tunnels or WireGuard, wildcard DNS obscurity, 2FA... There are many options.

Defense in depth is the only way to put services on the internet.

topspin•22m ago
> Geoblocking, fail2ban

I use both on one port 22 host. Not much actually touches the server: maybe 5 hosts a day get banned. Meanwhile, China and the Netherlands are forever getting blocked and logged by geoblocking.

I check the 24h log window by country most business days. Some days China leads, other days the Netherlands pulls ahead. Almost never are any other countries close to those two.

yjftsjthsd-h•18m ago
I certainly agree with your general point, but it is very much my experience that just forcing public key authentication on ssh is good enough on its own. (Yes, I understand that by writing this on the internet, I have doomed us all to dealing with a sev zero openssh sshd RCE. Sorry in advance.)
SoftTalker•32m ago
This is a lot of complexity compared to just not having ssh open to the world (on whatever port you choose to use).

Restrict it to the networks where authorized users will be connecting.

zsoltkacsandi•17m ago
Or just using a VPN, Wireguard, or Tailscale if you don’t want to configure Wireguard yourself.
IronWolve•23m ago
Stacking is cool, but what happened to also having a firewall in front of it?!
orev•22m ago
Glad to see fwknop mentioned. Back when the idea of port knocking emerged, there was a lot of criticism about it. Then this came out, and not many seemed to notice.

This was before WireGuard and Tailscale, so the main option for remote access was IPsec or OpenVPN, which are both more complicated than most people want to deal with.

ggm•17m ago
A scheme like this is in the process of being standardised by Peter Gutmann who knows what he is doing.

https://datatracker.ietf.org/doc/draft-gutmann-ssh-preauth/

somat•8m ago
The enlightened trick is to run ssh on port 443.
streetfighter64•7m ago
AI writing, sigh...

> to be unreachable: no banner, no version string,

> It works, but it has a real weakness:

dataflow•6m ago
[delayed]
usernametaken29•5m ago
I don’t know why this wasn’t mentioned before but why not use a Firewall. If you’re using a virtual box like Hetzner or Scaleway you can specify an ip or range at the router level. For all intents and purposes this removes public exposure. Scaleway also has a cheap VPN bridge. So you never need to connect via the public internet if you don’t want to… hardly gets more secure than that

Magnitude 7.7 Earthquake – 68 km NNW of Ende, Indonesia

https://earthquake.usgs.gov/earthquakes/eventpage/us6000tkt2/executive
151•Bender•4h ago•30 comments

Qwen 3.8 27B

https://huggingface.co/Qwen/Qwen3.8-27B-FP8
998•erdaltoprak•14h ago•643 comments

Going Dark, and the era of law enforcement hacking

https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/
267•vslira•8h ago•133 comments

The other Sean Byrne doesn't exist

https://conic.al/writing/the-other-sean-byrne-doesnt-exist/
7•rdl•1h ago•1 comments

The Ploopy A+ Trackball Is Here

https://blog.ploopy.co/the-aplus-is-finally-here-499
68•big_toast•4h ago•35 comments

I close SSH port 22 (and what I use instead)

https://www.michelebologna.net/2026/ssh-port-22-fwknop-single-packet-authorization/
16•speckx•4d ago•17 comments

Google is making private AI practical with homomorphic encryption

https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/
328•u1hcw9nx•13h ago•195 comments

eigendrum

https://eigendrum.com/#p=circle
83•bookofjoe•7h ago•19 comments

AI Driven Testing

https://app.deltix.ai
15•oneounceman•2h ago•7 comments

Simplifying and Refactoring Introductory Calculus

https://arxiv.org/abs/1811.03459
63•E-Reverance•5h ago•19 comments

RustDesk now supports true unattended remote access on Wayland

https://rustdesk.com/blog/unattended-remote-access-wayland/
251•rustdesk•13h ago•109 comments

Show HN: Rent vs. buy, backtested across 241 US metros with pinned data

https://github.com/assumptionsshown/RunTheNumbers
4•newroots•49m ago•1 comments

Show HN: A website for exploring historical photographs of my city

https://yesterdays.maprva.org/
16•uneekname•2d ago•7 comments

Firefox is now the last major browser that still supports uBlock Origin

https://www.pcworld.com/article/3212428/firefox-is-now-the-last-major-browser-that-still-supports...
660•DemiGuru•10h ago•250 comments

Unearthing a 31 year old Easter egg in Ecco the Dolphin

https://32bits.substack.com/p/under-the-microscope-ecco-the-dolphin-98c
59•bbayles•2d ago•14 comments

AI by Hand

https://www.byhand.ai/
244•sans_souse•13h ago•19 comments

Hi-Fi Tape Recorder Changed Radio Forever

https://spectrum.ieee.org/magnetophon-laugh-track
31•Jimmc414•3d ago•3 comments

Super Mario Derivations

https://fzakaria.com/2026/08/05/super-mario-derivations
81•domenkozar•1w ago•14 comments

I turned my RSS feeds into an e-ink newspaper to stop reading on my phone

https://heyjonny.dev/posts/rss-to-eink-newspaper/
168•speckx•14h ago•65 comments

Introducing Toast 1

https://www.mixedbread.com/blog/toast-1
190•mplappert•14h ago•59 comments

Maximizing the value of your Claude Code sessions

https://claude.com/blog/maximizing-the-value-of-your-claude-code-sessions
165•twapi•13h ago•106 comments

Ultraviolet Bird Photography

https://uvbirds.com/
129•EndXA•1w ago•23 comments

Turbo Pascal on CP/M, MSX-DOS and MS-DOS

http://pascal.hansotten.com/delphi/turbo-pascal-on-cpm-msx-dos-and-ms-dos/
85•rbanffy•2d ago•29 comments

GLM-5.3: Frontier coding with emergent cyber capabilities

https://z.ai/blog/glm-5.3
1058•pella•1d ago•525 comments

Why does Opus 5 feel worse to work with?

https://mun-logadan.github.io/why-does-opus-5-feel-worse/
820•numeri•19h ago•749 comments

Show HN: Ember – Redshift safe color palettes

https://github.com/carpdiem/ember
80•carpdiem•5d ago•17 comments

Racket v9.3

https://blog.racket-lang.org/2026/08/racket-v9-3.html
51•privong•11h ago•1 comments

Show HN: Mole – Deep research agent for your terminal

https://github.com/lajosdeme/mole
58•lajosdeme•10h ago•9 comments

Seven books I keep close because I love them

https://blog.plover.com/2026/08/02/
326•surprisetalk•14h ago•147 comments

New Lower and Upper Bounds for the Grothendieck Constant

https://arxiv.org/abs/2608.11158
43•surprisetalk•9h ago•8 comments