It is not that SSH is less secure, it is that crackers attempt to brute force SSH servers [...]You still use passwords?
Out of the box debian has passwords enabled and certificates allowed but not mandatory.
I can guarantee at least 90% of all debian installations do not have the defaults changed (let alone any of the other flavours of linux).
This is the precise reason I get dozens of attempts a minute on
my firewall port 22.