4 ms·
To clarify: this is to counter the statement that security through obscurity is a good thing. Yeah, that worked out well for the Enigma and countless other sys
by sinrostro 11y ago
To clarify: this is to counter the statement that security through obscurity is a good thing. Yeah, that worked out well for the Enigma and countless other systems.
- nickpsecurity 11y agoThat commenter was replying to me with more nonsense like your selective example of Enigma that barely fits into the discussion at all. Worse, your example actually supports my side's position: they cracked the best crypto they had the second they knew how it worked and no methods were in place to reliably detect this. Today, they crack the complex systems and protocols people are using shortly after figuring out how they work as quality is so bad and everyone uses same ones. The modern example of enigma would be people using Linux desktops instead of Windows, Foxit instead of Adobe, unusual-but-good web servers instead of Apache, and so on to hope attackers not knowing will keep them safe. And it usually works, too, unless it's a targeted attack by pro's. That's saying something. ;) My method combines vetted mechanisms with ways that adhere to their guidelines for secure usage, is directed by tools designed by security pro's, largely invisible to users, require a hack on system to find, and force custom, difficult attacks. One can mathematically prove that my strategies possess the traits I claim along with immunity from some issues and vastly improved probabilistic security against most others. So, all the evidence is on our side in theory and the field results where compromise is rare for us even in face of pro's whose bonuses require it. Feel free to refute this by showing me how everyone using two browsers, OpenSSL, or a desktop OS (Windows) with no changes on the same platform kept them safe from major attacks. Or led to such a high failure rate for attackers that hacks were actually worth of news rather than scaremongering. My people were safe with my methods: some systems crashed or raised exceptions while many had no problems. I'm guessing you standardize-and-open types had the same experiences? No? :P