Cyber criminals follow patterns, starting with very low-effort trolling for new services without much defenses. Bots scan the internet for open services, enumerate them, and try to gain access. If they find some, they will use a tiny amount of effort to see if the target might be worth exploring. If it seems profitable, the cybercriminal will spend more effort on things like account enumeration, login brute force, scanning for commonly exploitable methods, phishing. The more they find, the more they're willing to invest in exploiting it. But a bot can perform a ransomware hijacking of a newly detected open service all on its own, so it doesn't take much.
Simple mitigations can be very effective in holding back their interest. Captchas, rate limiters, error pages with no information leakage, block lists of low-reputation IPs, or outright blocks of countries you don't do business with. They make the difference between 50k login attempts per minute, or crickets.
Don't use port knocking tho. It technically works, but is embarrassing, like a grown man in a trilby. Something else (like rate limiting combined with certificate auth) will be more effective and less weird.
If you know a site has a 4-words policy, the xkcd pw has very low entropy, but if you use this strategy on a "any pw goes" site, a bruteforcer would have to test all lengths upto 25 chars before finding yours (sort of).
So in the port-knock case, it is probably a rather poor method in the specific case that I am on some remote network, and the evil 3rd party is actively sniffing my traffic from my client to my server and can record the knocks. If I have a simplistic knock sequence and they sniff it, they can replay it and get access to my https. But, if we are talking about some 3rd party that only knows a service may be up on the host newly.minted.cert.ccTLD, then it is FAR less likely that they can ALSO sniff my port knocking sequence and start abusing my new TLS service. The chances become almost ridiculously low for this to occur.
So I agree that simplistic port knocking is sort of bad in the long run for cases like "I am often on a hostile network but still want to talk to my home server securely" but would work wonders for "soon after the cert is signed, someone scans my TLS boxes ip".
Somewhat related, I've never set up port knocking but I've been wondering how hard it would be to set up TOTP-flavored port knocking. The basic idea would be to select the pattern of "knocks" the same way TOTP generates a code, I'm not sure how much it would improve things though.
How so? Iirc, the entropy calculations assume that the attacked is aware passphrases are used. The eff-long word list often used for xkcd-style passphrases has 7776 words. So on average it would take 7776^4/2 attempts to guess one (randomly generated) 4-word passphrase, comparable to a truly random 8-9 character password with special chars. As the comic points out, people tend to be pretty bad at remembering random sequences of characters and therefore often often use combinations of common words and apply non-random substitutions and patterns, resulting in much lower entropy for those passwords.
Of course, everyone should use a password manager in the first place, but for cases where people don't or they need to reliably remember it (master passwords and critical ones), xkcd-style passphrases are a good and secure option.
Anyone even thinking about port knocking should look at fwknop.
For personal use, I do feel that Wireguard or managed Wireguard setups like Tailscale are so easy to use that putting everything behind a VPN is cheap insurance and even convenient, since it takes care of NAT traversal for you.
I also use blackholing (with fail2ban) and non standard ports (for ssh) - but just as a way to quiet down log files rather than ascribing much ion the way of security benefits to them.
Just switch to IPv6: good luck scanning a /64. :)
:-)
I had IPv6 on my home desktop for several years before I switched ISPs a few months ago.
My new ISP does not offer IPv6 on their residential network… but their mobile telco subsidiary gives it out to smartphones (IPv6-only). ¯\_(ツ)_/¯
90% of desktops/laptops get a 192.168.0.x address. Maybe some do ipv6 as well