Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unlike port knocking (which folks seem to be mentioning a lot), this seems like it only has 1,000,000 possible locations that can rapidly be scanned.

Knocking has multiplicative growth and so many more possibilities.

Perhaps you could include honeypots in the IPv6 range where you’re not bound that block the user, but this seems less reliable overall.

I’m sure this is just great fun, but perhaps not something to think of as secure so much as a fun idea — to make it secure you might want to use a system more like knocking.



Port knocking sucks (subject to replay attacks).

Look at Single Packet Authentication. Fwknop is a solid implementation.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: