5 ms·
Making something closed source does not make your product more secure, it only makes it harder to look at. Determined people will still try to understand how yo
by laburn 9y ago
Making something closed source does not make your product more secure, it only makes it harder to look at. Determined people will still try to understand how your software works in order to accomplish their goals.
- AFNobody 9y agoHashing passwords is security through obscurity by that reasoning. That does not make them less of a security function. Just something to keep in mind.
- Sylos 9y ago"Security by obscurity" tries to keep the way that your encryption method works obscure, it does not try to keep a specific key obscure. For example, if your way to encrypt works like this: 1) Shift all letters along by 5. 2) Cut out every second word and put them behind the message in order. 3) Whenever there's an f, s or y in a word, double up that word and shift the second word's letters by 7. Then if your enemy figures out how your method works, you have to come up with a completely different method. The opposite to security by obscurity would instead once come up with a method that entirely depends on a key. You can then publicize that method (or not), and if your enemy finds out your key, you just choose a new key and you're fine again.
- wvenable 9y agoSecurity through obscurity is a valid and effective tactic -- it's simply ineffective on it's own.
- Skunkleton 9y agoTo reinforce your point, see all pre-modern crypto techniques. It cannot be argued that they worked, and they were all certainly security through obscurity.
- onion2k 9y agoAren't most examples things where it didn't work? The most famous case is the German "Engima" device from WWII (hardware- and 'software'-based, but cracked and readable for years before the Germans knew because they believed it was both obscure and effective) but it's wholly possible that most schemes were broken eventually. Keeping an obscure system secret is really hard, especially against a motivated attacker.
- azag0 9y agoEnigma wasn't hard through obscurity. The Allies had the Enigma machine long before they were able to crack it. It was hard because with the equipment of the day, it was pretty much unbreakable in the same way that prime-number based cryptography is today. It was only A. Turing developing a completely novel kind of machine (https://en.wikipedia.org/wiki/Bombe https://en.wikipedia.org/wiki/Bombe) that enabled the decryption. In the same way that quantum computers could break the current cryptography easily. It's not obscurity, it's assuming that some (mathematical) task is hard.
- JetSpiegel 9y agoDon't forget about the Polish. They too broke the encryption before, but then they were invaded, and no precision machinery was available to increase the number of rotors to 10. https://en.m.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma https://en.m.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma Turing did it too, independently.
- deleted 9y ago[deleted]
- azag0 9y agoDidn't know about that! But it seems they were able to break the system only while the Germans where sending the settings of the plugboard in the header of each message. Once that was changed in the early 1940, their decrypting techniques wouldn't work anymore. Btw, from the wikipedia article: "lazy cipher clerks often chose starting positions such as "AAA", "BBB", or "CCC"" Weak passwords were an issue already back then.
- stevekemp 9y agoWhich reminds me of how this site was hacked: https://news.ycombinator.com/item?id=639976 https://news.ycombinator.com/item?id=639976