Spoofing TCP is useless - you actually need to receive all the packets sent to the original TCP, which means either you are already on the receiving path, or managed to put yourself on it e.g. through a BGP route advertisement - either way, it leaves some trail and much harder to carry out.
(And even so, the attacker still has to go through SSH authentication or an SSH vulnerability)
See: https://en.wikipedia.org/wiki/TCP_sequence_prediction_attack
It's not practical but it is possible. It was more effective in the past when operating systems had more predictable initial sequence numbers. Famously this is how Kevin Mitnick (allegedly?) attacked Tsutomu Shimomura.
IIRC even SYN cookies are older than 20 years at this point.
RST attacks in particular are common enough to make TCP completely unsuitable for reliable long-term connections. And since TCP is also unsuitable for short-term connections, that leaves UDP the only option.
Now, RST attacks are still a thing, but mostly irrelevant to this port knocking alternative.
What do you mean "original TCP"? I'm talking about an attacker creating a new TCP connection with a spoofed source address.
> which means either you are already on the receiving path
Yes, I believe that's the threat model under discussion here. Tepix mentioned an attacker who can intercept a packet, which I believe means the attacker is already on the receiving path.