Using telnet makes me feel a little dirty and a lot alive. Using it over wireguard seems like taking a 60s muscle car and adding brakes that actually work before a track day; probably not a bad idea.
Nice! Wireguard was not around when I was using Internet-facing SSH in a previous job.
Adding it to the recommendations.
It is also fairly easy to DoS SSH by having too many connections in the authentication state leaving no slots open, which SSHGuard is useful to counter.
Apart from that, SSH's intrinsic security is the same, but if you have password authentication enabled, you are only as strong as the weakest password.
A number of configurations also ship with ssh root login enabled by default. For example if you setup a new Linode VPS. You need to add a user, remember to at least turn off root access and probably also password access. I get why they're doing it because it easier, but yeah ... not a huge fan of this configuration.
Wireguard is just a very simple network bridge. Whoever has the key can send anything over the network. There isn't a robust mechanism required to keep the key, to revoke it, to audit its use, to enable it to only provide access to specific applications. It doesn't have 1/20th the features SSH has, and SSH itself lacks a bunch of security features.
Bottom line is that you should only use Wireguard if you need a simple encrypted network bridge. It does not remove the need for other more complex security products.
It's really not. It's a technical question with many technical answers, thankfully they were provided by other commenters before you posted this.
If anything, it's similar to asking if a bike is faster than a car, to which you would reply than a bike might be faster in traffic because of small size but slower over long distances because of propulsion. It is possible to compare apples and oranges over specific axes.
Cars and bikes are both fine for point to point travel. They'll each give you a vastly different experience though. It"s prolly better to stick with what you know how to use, in my opinion. You're likely gonna have a bad day if you crash and die.
Edit: deleted false information about TLS.
And honestly some of the issues that were there are not something preventable by limiting oneself to even 50 LOC. I don’t want to speculate how they came to be though. It’s really baffling.
Here's a good summary:
https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
Contrast this with how easily and well Wireguard was integrated into OpenBSD.