3 ms·
"if you can reduce risk probabiloty with zero cost..." since when is obscurity zero cost? You've seen how much denuvo and vmprotect cost? Can you name any free
by shuringai 6y ago
"if you can reduce risk probabiloty with zero cost..." since when is obscurity zero cost? You've seen how much denuvo and vmprotect cost? Can you name any free free code obfuscator besides proguard that actually works? Can you name one that supports golang or rust?
Security trough obscurity is considered bad because it's not zero-cost, and the investment you put into it might rather go into actual security
- sedatk 6y agoChanging the port number is quite cheap.
- austincheney 6y agoThat is also not a security control.
- sedatk 6y agoTheoretically, yes. But if it makes you get off the radar of some malicious attacker who is capable of exploiting you, then the mission is accomplished.
- austincheney 6y agoNot at all. The attacker will find it within a minute after running a port scan.
- sedatk 6y agoNot applicable to mass scanners. They simply can’t afford scanning all ports for all hosts.