And, of course, for any discussion of security, you need to specify what your threat environment is. Are you just locking down your home router, or are you running the first line of cyber defense for the CIA? He keeps moving the goalposts in order to knock down his opponents, which is why I can't take him seriously.
(Edit: For what it's worth, when I tried out knockd, it supported arbritrary port sequences, so you could easily have a 16 port sequence, making it as robust as you want. Timing however, was quite a pain. I had to use specific timeouts (relative to the RTT time from my network to my VPS), and manually enter each port in the sequence).
Personally, I've found that whitelisting IP's for SSH access, as well as a default block-all policy, disabled root login, and Key authentication have been enough to keep people out of my VPS.
Sure, seeing all of the denied traffic in the logs is annoying, but there's not much you can do about that (other than not log it).
Just remember that the port argument to `scp` is -P and not -p like it is for `ssh`. :p
He seems to be missing the point that this is only equivalent to a password if the attacker knows that it's there and can measure whether they've guessed correctly. Sure, if I tell someone that I've used a 48-bit password and allow them to get instantaneous feedback for each attempt, and don't block them completely after N guesses, it's not much of a barrier. On the other hand, if all they see is a non-responsive port and I make timing a factor and I do block them for guessing, it can significantly hamper their ability to make any guesses at the next (ssh) layer. Nobody's suggesting that the three-letter port knocking sequence should be the only security measure taken. It's purely an adjunct or enhancer for other measures, and for that it can be quite effective.
Yes: you can significantly reduce it by dynamically banning IP addresses which originate it.