3 ms·
Its another brick in the wall. As long as you're not fooling yourself into thinking it's all you need, it aids in not making things easier for people to figure
by wizard_2 17y ago
Its another brick in the wall. As long as you're not fooling yourself into thinking it's all you need, it aids in not making things easier for people to figure out and slightly raises the bar against intrusion. "Defense in Depth" is the only situation where I could consider obscurity a security layer.
Just because I keep my ssh servers up to date (disable passwords, root login, etc), doesn't mean I don't gain anything by having them listen a high port. The moment a 0-Day exploit is found (or maybe another Debian key generation bug) the security of not showing up on every script kiddies initial scans looking for unpatched ssh servers is worth something.