
Quoting Chris Samuel (chris@csamuel.org):
I was just wondering if that meant we were more of an attraction than other sites.
What I mean is merely that: Both personal experience with making ssh connections and long-term monitoring of logfiles, along with shirtsleeve estimates of credential combinatorics, suggests that brute-forcing sshds would require on average at minimum decades if not a lot more, except against literal 'joe' passwords (e.g., very common dictioanry words) that modern *ixes have for a very long time disallowed even the dumbest users to pick. And that's without rate limiting, fail2ban, non-standard service ports, and all the rest of that lot. And also that I have about 19 years of direct Internet exposure to illustrate the point.