3 ms·
Interesting analogy. You could extend the analogy to ASLR. ASLR randomizes the address just as you might randomize your SSH port. But no-one thinks of ASLR as "
by catern 6y ago
Interesting analogy. You could extend the analogy to ASLR. ASLR randomizes the address just as you might randomize your SSH port. But no-one thinks of ASLR as "security by obscurity" - it's a mitigation strategy like any other.
Thinking of the SSH port number as a "secret" in same way that libc addresses are "secrets" is an interesting and valuable perspective. It suggests that, like with ASLR, there should be some higher-level "linker" that gives this secret information (address of functions, SSH port number) to those who need it, and no-one else.