3 ms·
Keeping the details of your security setup secret or obscure is not security through obscurity. Security trough obscurity is using the secrecy of your security
by PMan74 9y ago
Keeping the details of your security setup secret or obscure is not security through obscurity.
Security trough obscurity is using the secrecy of your security setup as a pillar of that security.
It's perfectly sane to keep the details secret even if those details themselves don't form part of your security.
- laumars 9y agoI'd argue that the reasons for wanting to keep implementation details secret would be more political than for security. eg wanting to exaggerate your DR capabilities to would-be customers. Or using tech that works but has a bad image (like Perl). Or perhaps you're just releasing a commercial solution that leverages a lot of open source components and thus could easily be replicated by anyone else. I'm not saying these are good reasons, but they make more sense than the "security" argument because if your infrastructure isn't secure to begin with then it's pretty trivial to find out what is running even without the tech being published / open sourced; and if it is secure then it doesn't really matter if the details were published in the first place.