3 ms·
I'm surprised that "security by obscurity" is touted as a way reduce attacks. This is almost guaranteed to lead to less diligence in the code — and more risks.
by nemild 7y ago
I'm surprised that "security by obscurity" is touted as a way reduce attacks. This is almost guaranteed to lead to less diligence in the code — and more risks.
https://en.wikipedia.org/wiki/Security_through_obscurity https://en.wikipedia.org/wiki/Security_through_obscurity
- duxup 7y agoIndeed. I wonder how much that has to do with human nature thinking "well this is obscure" so then they don't secure it as if it was 'customer facing' or less 'obscure'.... and thus leave it more open than ever. I knew a place that assumed such things, crazy insecure. They also played the "well this shouldn't be exposed to the internet" game as well.
- MentallyRetired 7y agoIt's closed source, though. The whole codebase is obscure to them. Using it would be obscurity.
- sdinsn 7y agoObscurity isn't supposed to replace security, it just aids it. Note that the US government heavily practices this, with 'Suite A' cryptography. Most other governments have similar practices.
- 781 7y agoQuote from the same page: > In recent years, security through obscurity has gained support as a methodology in cybersecurity through Moving Target Defense and cyber deception.[9] NIST's cyber resiliency framework, 800-160 Volume 2, recommends the usage of security through obscurity as a complementary part of a resilient and secure computing environment.