> If a zero-day drops in OpenSSH...
Realistically, fwknop is more likely to have a vuln than OpenSHH. Last release was two years ago and the readme dates back twelve :/ Time will tell.
fwknop is a bit lower risk though. If all an attacker can do is open a port, they’ll still have to exploit OpenSSH.
Seriously. If a zero-day drops in OpenSSH, it's quite literally the end of the world.