2. Next he talks about this non-root listener issue. He
claims that you shouldn’t run your SSH daemon on a
non-privileged port because anyone can spin up a daemon
up there. Great point, except you can still do that even
if you run your main one on 22.
I don't think I understand this point at all. What is it that you're trying to say?Are you sure you understood the original post's point?
djc@capelis.dj:~$ nc -l -p 14
nc: bind to source :: 14 failed: Permission denied
nc: bind to source 0.0.0.0 14 failed: Permission denied
nc: failed to bind to any local addr/port
djc@capelis.dj:~$ nc -l -p 1414
^C
See the difference?(Edit: The original blog entry has now been edited to slightly clarify the wording. But the update mostly seems like an attempt to rapidly justify the author's original point.)