• 0 Posts
  • 7 Comments
Joined 1 year ago
cake
Cake day: June 27th, 2023

help-circle


  • But if they don’t know they have to knock “shave and a haircut” first, your job gets a lot easier and you’re dealing with a lot fewer nuisance password promptings.

    Very good explanation. And the benefits are even greater: because there is absolutely no response until the entire secret knock is correctly used, the random guy trying to get in doesn’t even know if there’s anyone at that address. (In fact, set up correctly, they won’t even know if there’s really a door there or not)


  • If you want to go down that path, a password is only security by obscurity.

    Port knocking is an extra layer of security, and one that can stop attackers from ever knowing your private server even exists. A random scanner won’t even see any open ports.

    Always bear in mind that any random guy advising people not to use port knocking may be doing it with malicious intent. I’m sure there’s someone out there advising that random passwords are a waste of time, and everyone should just use monkey123.




  • I have just done the same.

    Although Google are now promising 5 years of support for Pixel phones, Pixel phones are not a core business for Google, and as they have shown many times, Google will end projects at the drop of a hat with no regard for their customers.

    There are secondary Android companies like Samsung that promise long term security updates, but are always behind the publishing curve compared to Google. This means that malicious actors have the opportunity to study Google’s published updates to reverse engineer cracks that they then exploit.

    The current Android security update model is inherently insecure due to this issue. Until manufacturers are forced to update in a timely manner ( by which I mean simultaneously with Google) I won’t buy another Android phone.