6 ms·
hi. article author here. the feed url is very long, and parents can disable it entirely. so i guess it's fine.
by fjallstrom 11y ago
hi. article author here. the feed url is very long, and parents can disable it entirely. so i guess it's fine.
- pc86 11y ago> the feed url is very long What does this have to do with the security of the feed?
- s9ix 11y agohttp://security.stackexchange.com/questions/36870/is-including-a-secret-guid-in-an-url-security-through-obscurity http://security.stackexchange.com/questions/36870/is-includi...
- overcast 11y agoI'm getting the fear.
- emergentcypher 11y agoPut another way: all security is security through obscurity. Whether we're guessing URLs or brute-forcing passwords, logging HTTP traffic or keylogging someone's machine. I hardly see the difference. It's not easy to tell where "obscurity" ends and "security" begins.
- jedberg 11y agoObscurity is when the secret part is entirely based on one side of the transaction (I hope they don't find this URL) whereas security involves secrets on both sides that must be discovered (here is a key exchange where we both know a secret thing).
- chrisseaton 11y agoOne-time pads as long as the message aren't security through obscurity are they? There's no way to brute force them. No future maths or quantum computer could ever crack them.
- jameshart 11y ago'How the pad was generated' is the obscure part with OTPs.
- bmm6o 11y agoYou can usefully distinguish between the name/location/identity of the resource and credentials/password used to access it. "Security through obscurity" is a specific criticism that usually means that the system doesn't adhere to Kerckhoffs's principle.
- marshray 11y agoIt's Kerckhoffs's 2nd principle: "[The system] should not require secrecy, and it should not be a problem if it falls into enemy hands" Which gives rise to the idea of "security though obscurity" is bad. A system is said to rely on obscurity if the bad guy learning any facts about it (other than the special secret keys) represents a compromise. https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle
- nommm-nommm 11y agoNo, theres a huge difference. Security through obscurity means that if the details of the algorithm are known then your secrets are no longer secret. It relys on keeping the encyption method itself secret. Compare with most good encryption methods, if you know which algorithm was used to encrypt my hard drive you cant use that information to decrypt it. The algorithm is published and the enemy knows the system but the system is still secure.
- andreasklinger 11y agomost likely tokens given it's for feeds you have to (most likely) manually regenerate them
- fiatjaf 11y agoIf you can guess a really long URL you probably can also guess all information about any children you want.
- xyclos 11y agoI am also intrigued by this. Would you mind sharing what other types information the feed provides?
- fjallstrom 11y agosure! - what lunch is being served in the cafeteria - homework and due dates - private messages from teachers (not the full message, just a notification) - reminders like "bring ice skates"
- thirdsun 11y agoThat is very impressive - so impressive that I never see it happen here in Germany at some point.