1. firewall port-knocking to block scanning and attacks

I would love to see a mode like freenet's silent bob, where connectors
must prove probable knowledge of the host key before the node will

5. block sending host key fingerprint for invalid or no username

This makes some sense...

1. Client may request proof of host private key.
2. Client must authenticate.
3. Client may request a copy of the host public key.

