@gemlog I've read a book on cybersecurity as a teenager so my passwords will take years to brute force. I remember getting these weird looks:
— Are you nuts, why is your password 20 characters long?!
— Best practice, you know… 🤭
But yes, disabling them completely is a valid point.
Using non-standard ports for ssh is also a good practice. Looking at cryptominers trying to get into your web server is entertaining, sshd — not so. And that "-p" doesn't make scripts less readable in a slightest.