This seems bad? - SSH3 is a bad name: this isn't a successor to SSHv2 and will only cause confusion - The authors don't seem to understand that SSHv2 predates all of their chosen technologies, and provides "robust and time-tested mechanisms" they claim to be adding - How is "hiding your server behind a secret link" a feature? This is, at best, security through obscurity, which can be layered on any network protocol (…
This isn't security through obscurity. The url would be a secret. This is a form of capability security, where to connect to the server you must be able to name the server.
A URL with a secret is, in my opinion, far more sane than port knocking, and will be much more efficient as well.
> (i.e. https://security.stackexchange.com/questions/148292/why-is-o...)
Your link doesn't support your statement at all. No one there answers "here's why oid is less secure", they say the opposite.