Hmmmm. I don't know if I buy that. If the pattern is not cryptographically secure, then you're still vulnerable to man in the middle, and if it is cryptographically secure, wouldn't you get roughly the same security by just doing standard SSH key based auth?