SSH protocol version exchange is before key exchange. Is this not easily identified in both Clint and server side packet analysis?
I appreciate that SSH can be obsfucated via an SSL tunnel but the article didn't come at that angle.
The article itself even states: >with SSH everything goes dark right after the initial capabilities exchange.
So... What say about before the exchange?