It looks as if there has already been quite extensive discussion on the topic of default ssh server settings in debian.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774793 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774711 So I don't think I have much more to add to that. Something else to consider though is that even if the defaults are improved upon some users may have an existing debian install which they then run freedombox-setup on, leaving them with not so good settings.
signature.asc
Description: Digital signature