There is a nice sshd option (-T) that tells you what it's really doing. Just run
sudo sshd -T | grep password sudo sshd -T | grep passwordsshd -T reads the configuration file and prints information. It doesn't print what the server's currently-running configuration is: https://joshua.hu/sshd-backdoor-and-configuration-parsing
Every configuration change immediately applies to every new connection - no need to restart the service!
Yay, they reinvented inetd too!