I wouldn’t characterize that example as “not smart” to be honest. I’m not particularly smart, but if someone has gone through the trouble of changing their secure socket port from 22, I would realize there would be more work and time involved in finding the actual port, and then it would be a safe assumption that, if found, it would have significantly more security hardening than the average port 22 because clearly the admin knows enough to change ports. So I might even characterize it as smart to not go after ssh ports that are not 22.