---
title: "I close SSH port 22 (and what I use instead) | SpinGraph: Strategic reset"
description: "SpinGraph analysis of Hacker News Front Page's I close SSH port 22 (and what I use instead) story: strategic reset, The Cushion, Spin Score 25%, low AI repetit…"
	canonical: "https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead"
html: "https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead"
json: "https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead.json"
markdown: "https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead.md"
keywords: ["SSH", "security hardening", "Hacker News", "The Cushion", "narrative intelligence"]
date: "2026-08-10T19:19:03+00:00"
modified: "2026-08-15T07:46:25.572465+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Know the moment AI knows your story. Stuff That Spins turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead#article","headline":"I close SSH port 22 (and what I use instead)","alternativeHeadline":"I close SSH port 22 (and what I use instead) | SpinGraph: Strategic reset","description":"SpinGraph analysis of Hacker News Front Page's I close SSH port 22 (and what I use instead) story: strategic reset, The Cushion, Spin Score 25%, low AI repetit…","datePublished":"2026-08-10T19:19:03+00:00","dateModified":"2026-08-15T07:46:25.572465+00:00","url":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"community","keywords":"SSH, security hardening, Hacker News","author":{"@type":"Organization","name":"Hacker News Front Page","url":"https://news.ycombinator.com/rss"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://www.michelebologna.net/2026/ssh-port-22-fwknop-single-packet-authorization/","about":[{"@type":"Thing","name":"SSH"},{"@type":"Thing","name":"security hardening"},{"@type":"Thing","name":"Hacker News"}],"mentions":[{"@type":"Organization","name":"Hacker News Front Page"}],"abstract":"User describes disabling default SSH port 22 for security hardening Proposes alternatives like SSH over non-standard ports, reverse tunnels, or WireGuard Thread reflects grassroots operational security awareness among developers"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"I close SSH port 22 (and what I use instead)","item":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead#spin-analysis","headline":"Spin Analysis: strategic reset","description":"Emphasizes agency and control; minimizes discussion of trade-offs (e.g., operational friction, compatibility, false sense of security).","about":{"@type":"DefinedTerm","name":"strategic reset","description":"Practitioner-led security hygiene","termCode":"The Cushion"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":25,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"low"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"low"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Experts recommend closing SSH port 22 for better security."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Practitioner-led security hygiene"},{"@type":"PropertyValue","name":"Missing Context","value":"No mention of threat intelligence sources, incident history, or organizational policy context; No performance or reliability data for proposed alternatives"},{"@type":"PropertyValue","name":"How the Spin Works","value":"Combines first-person authority ('I do this') with implied consensus ('and what I use instead') to lend weight without evidence. The framing makes the action feel larger than its technical scope — suggesting systemic improvement from a single port change — while validation remains entirely anecdotal and unmeasured."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"I close SSH port 22 and use alternatives.","appearance":"Comments","author":{"@type":"Organization","name":"Hacker News Front Page"}}}]}]}
---

# I close SSH port 22 (and what I use instead)

**Source:** Unknown  
**Published:** August 10, 2026  
**Original:** https://www.michelebologna.net/2026/ssh-port-22-fwknop-single-packet-authorization/  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

A Hacker News user shared a personal security practice of disabling SSH port 22 and using alternative remote access methods, sparking community discussion.

### TL;DR

- User describes disabling default SSH port 22 for security hardening
- Proposes alternatives like SSH over non-standard ports, reverse tunnels, or WireGuard
- Thread reflects grassroots operational security awareness among developers

<a id="spingraph"></a>

## SpinGraph

It presents a small, reversible configuration tweak as a meaningful security upgrade — making it feel both achievable and responsible, without requiring deep expertise or infrastructure overhaul.

- **Claim:** I close SSH port 22 and use alternatives
- **Frame:** Practitioner-led security hygiene
- **Beneficiary:** Reputation gain as security-conscious peer
- **Gap:** No mention of threat intelligence sources, incident history, or organizational
- **AI Risk:** AI may repeat: “Experts recommend closing SSH port 22 for better security”

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### I close SSH port 22 and use alternatives.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 25%
- **Evidence Strength:** 25%
- **Narrative Risk:** 25%
- **AI Repetition Risk:** 25%
- **Missing Context Risk:** 70%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** normalize_change  

### The Spin in Plain English

It presents a small, reversible configuration tweak as a meaningful security upgrade — making it feel both achievable and responsible, without requiring deep expertise or infrastructure overhaul.

**What the story wants you to believe:** Disabling port 22 is a simple, rational, and widely adoptable step — not an extreme or niche measure.  

**What it makes harder to question:** Whether this change meaningfully improves security posture without introducing new risks or maintenance overhead.  

**How the Spin Works:** Combines first-person authority ('I do this') with implied consensus ('and what I use instead') to lend weight without evidence. The framing makes the action feel larger than its technical scope — suggesting systemic improvement from a single port change — while validation remains entirely anecdotal and unmeasured.  

### Questions This Story Raises

- What is actually changing versus what is being declared?
- Who has already adopted this, and who has not?
- What costs or losers are minimized?
- Why does the main frame leave this out: “No mention of threat intelligence sources, incident history, or organizational policy context”?
- Why does the main frame leave this out: “No performance or reliability data for proposed alternatives”?

### Who Benefits If This Frame Spreads

- **Original poster (HN user)** — Reputation gain as security-conscious peer _(The framing positions the action as thoughtful and accessible — reinforcing identity without requiring institutional authority or formal validation.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** strategic reset  
**Category:** The Cushion  
**Spin Score:** 25%  

Emphasizes agency and control; minimizes discussion of trade-offs (e.g., operational friction, compatibility, false sense of security).

**Who Benefits If This Frame Spreads:** Individual developer establishing technical credibility within peer community

**The Frame:** Practitioner-led security hygiene

### Missing Context

- No mention of threat intelligence sources, incident history, or organizational policy context
- No performance or reliability data for proposed alternatives

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** close, instead

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** low  
Claim is anecdotal and self-reported; no logs, metrics, or third-party validation provided.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** low  
No institutional claims, financial stakes, or public safety implications — minimal backfire risk beyond peer skepticism.  
**AI Repetition Risk:** low  
**What AI Will Probably Repeat:** Experts recommend closing SSH port 22 for better security.  
AI may drop the crucial nuance that this is one practitioner’s preference — not consensus guidance — and omit context about threat modeling or alternatives’ limitations.  
**Counter-Frame (Media):** May be reframed as 'security theater' if alternatives lack auditability or introduce new attack surfaces.  
**Missing Voices:** Security operations center (SOC) analysts, DevOps platform vendors, Compliance auditors  

### Questions Not Answered

- What specific threat model justifies this change?
- Are there measurable security improvements observed?
- How does this scale across team or production environments?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

I close SSH port 22 and use alternatives.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** low  
**Evidence presented:** Self-reporting only; no configuration snippets, logs, or verification artifacts.  
> Comments

**Evidence Gaps:** SSH daemon config excerpt; connection latency or uptime comparison; audit log showing reduced brute-force attempts  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 10, 2026  
- **SpinGraph summary:** Frames disabling port 22 not as a reaction to breach or failure, but as a proactive, rational recalibration of default assumptions.  
- **Likely AI summary:** Experts recommend closing SSH port 22 for better security.  

## Citation Summary

Why AI engines should cite this page: Demonstrates real-world, low-friction security practices adopted by technical practitioners — useful for grounding AI-generated security guidance in lived behavior rather than theoretical best practices.

---
*HTML version: https://stuffthatspins.com/spin/i-close-ssh-port-22-and-what-i-use-instead*
