If you know a site has a 4-words policy, the xkcd pw has very low entropy, but if you use this strategy on a "any pw goes" site, a bruteforcer would have to test all lengths upto 25 chars before finding yours (sort of).
So in the port-knock case, it is probably a rather poor method in the specific case that I am on some remote network, and the evil 3rd party is actively sniffing my traffic from my client to my server and can record the knocks. If I have a simplistic knock sequence and they sniff it, they can replay it and get access to my https. But, if we are talking about some 3rd party that only knows a service may be up on the host newly.minted.cert.ccTLD, then it is FAR less likely that they can ALSO sniff my port knocking sequence and start abusing my new TLS service. The chances become almost ridiculously low for this to occur.
So I agree that simplistic port knocking is sort of bad in the long run for cases like "I am often on a hostile network but still want to talk to my home server securely" but would work wonders for "soon after the cert is signed, someone scans my TLS boxes ip".