7 ms·
This is an attitude that I really hope leaves the industry eventually, because in truth people use security through obscurity all the time. Using it exclusively
by easterncalculus 5y ago
This is an attitude that I really hope leaves the industry eventually, because in truth people use security through obscurity all the time. Using it exclusively or in place of real measures is when it becomes a problem.
Ask any IT professional who's had to patch zero days on internet-exposed systems whether they think changing the default port is useless, and practically all of them will tell you that it at least cuts down on logs, and means that you almost definitely won't get hit that first day with all the other people by script kiddies scanning the internet. Not posting your internal network diagrams, even though your security is 'open design', means that when someone sends the right email and breaches your perimeter, they still have to scan for what to go after. Additionally, this belief is almost exclusively held dogmatically by the private sector - classified government networks don't get hacked nearly as often as even your air-gapped corporate ones. Obscurity is never a replacement for 'true' security measures, and should only be added on after, but for a system you actually want to protect in the long term some amount of is often very useful.
- AlexAndScripts 5y agoJust changing my SSH port to 900 has reduced the amount of brute force by a fraction.
- AlexAndScripts 5y ago*too a fraction, not by a fraction
- easterncalculus 5y agoThat is reason enough, in my view. If you're going to install fail2ban for instance I feel that you might as well also change the port.
- TameAntelope 5y agoAnd conversely, I hope the attitude that security through obscurity is effective leaves the industry, because the people who are using it (and you're right it is common) are not as safe as they think. It's a complacency problem. Changing the port of your SSH server to 900 may, in isolation be a fine thing to do, but when actually done in the real world it tends to be a substitute for keeping your SSH server up-to-date, or more realistically, even remembering you opened up the port to the world in the first place. The concern isn't and hasn't been the IT professional patching zero-days, it's the IT professional who doesn't know what a zero-day is. Once you've worked with those people, after they've been referred to you by the FBI, you start to understand the harm Security Through Obscurity causes.
- easterncalculus 5y agoUltimately like most things in security this is an education problem. It's all about people knowing more than what some online "secure SSH guide" tells you, including recommendations to "secure" your machine like changing the port or "disabling root login", etc. Most of it under some scrutiny isn't actually that substantial, but a lot of professionals are out there are treating it like dogma. > Changing the port of your SSH server to 900 may, in isolation be a fine thing to do, but when actually done in the real world it tends to be a substitute for keeping your SSH server up-to-date, or more realistically, even remembering you opened up the port to the world in the first place. It's interesting that you frame it this way, because I was thinking of this as the opposite: that the 'theory' being taught is not changing the port because security through obscurity is bad, and that the 'practical' solution is doing all of the things you mention it shouldn't be a substitute for, and only then adding obfuscation methods. I think we're saying the same thing, that you can't substitute obfuscation for 'legitimate' security measures, but from different perspectives.