this post was submitted on 22 Apr 2026
1331 points (99.6% liked)
Technology
84041 readers
3062 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
People like to think in black and white, but you're definitely right. Having your SSH server on port 36271 will likely stop a ton of drive by attacks because they simply won't check it. Having it only listen on IP6 would stop almost all of them because you can't trawl the IP6 space efficiently. These are "obscurity", but they have real benefits. The idea that "obscurity" doesn't help is just a meme that people love to quote because it's a great single sentence with some nice rhyming "security by obscurity". I assume the reason it became a meme is because tons of products fully relied on obscurity; I still see it all the time. As you said, it's all layers.
Yep! I don't know a single engineer who would say that security by obscurity is never useful. Everyone knows, as you said, to put SSH on a random port. It's the first step you do to secure a server.