Ask any IT professional who's had to patch zero days on internet-exposed systems whether they think changing the default port is useless, and practically all of them will tell you that it at least cuts down on logs, and means that you almost definitely won't get hit that first day with all the other people by script kiddies scanning the internet. Not posting your internal network diagrams, even though your security is 'open design', means that when someone sends the right email and breaches your perimeter, they still have to scan for what to go after. Additionally, this belief is almost exclusively held dogmatically by the private sector - classified government networks don't get hacked nearly as often as even your air-gapped corporate ones. Obscurity is never a replacement for 'true' security measures, and should only be added on after, but for a system you actually want to protect in the long term some amount of is often very useful.
It's a complacency problem. Changing the port of your SSH server to 900 may, in isolation be a fine thing to do, but when actually done in the real world it tends to be a substitute for keeping your SSH server up-to-date, or more realistically, even remembering you opened up the port to the world in the first place.
The concern isn't and hasn't been the IT professional patching zero-days, it's the IT professional who doesn't know what a zero-day is. Once you've worked with those people, after they've been referred to you by the FBI, you start to understand the harm Security Through Obscurity causes.
> Changing the port of your SSH server to 900 may, in isolation be a fine thing to do, but when actually done in the real world it tends to be a substitute for keeping your SSH server up-to-date, or more realistically, even remembering you opened up the port to the world in the first place.
It's interesting that you frame it this way, because I was thinking of this as the opposite: that the 'theory' being taught is not changing the port because security through obscurity is bad, and that the 'practical' solution is doing all of the things you mention it shouldn't be a substitute for, and only then adding obfuscation methods.
I think we're saying the same thing, that you can't substitute obfuscation for 'legitimate' security measures, but from different perspectives.
However, I read your comment to imply that the author lost credibility with their take on security through obscurity. This seems like the exact kind of harmful binary thinking the article addresses. The author presents a more nuanced take on a mantra, and for daring to do so, you dismiss them.
Obscurity can be useful when overlaid onto stronger security. It's why are military tanks camouflaged and not pink or hi-vis yellow.
Do you post all your internal documentation onto a public repo?
If not you are practicing some security by obscurity.