3 ms·
This is unfair as it is not what GP said. It was simply pointed out that infosec professionals do not say that, which is true. There a wide difference between w
by yaantc 4y ago
This is unfair as it is not what GP said. It was simply pointed out that infosec professionals do not say that, which is true. There a wide difference between what one can read on the web and the security professionals position on this. You focus on the public perception, GP the professional one. And it's worth pointing this out IMHO particularly because there is such a large mismatch.
If one reads the Common Criteria specifications [1], they actually require obscurity at some level (didn't check which one, for sure EAL4 and above do). Specifically, all the design must be kept secret so obscured to attackers. This is serious stuff, requiring secure design facilities for example. The goal is to force an attacker into a complex (so costly) reverse engineering.
There is a too common vision of security as an absolute thing, it's either secure or not. This is already a simplification for algorithms, but there why not. But for secure systems it's definitely not sufficient, and you agree with this like GP does it seems. Professionals must balance the cost of security vs. the cost of an exploit. And obscurity do raise the cost of an attack, so it makes perfect sense to consider it. And it is considered (see CC).
So GP summary that obscurity is justly considered by professional, and makes sense as long as it's not the only defense, seems correct to me and worth mentioning. You have taken it as a criticism but you shouldn't: it essentially also says what you said, that obscurity has its proper place in security.
[1] https://www.commoncriteriaportal.org/cc/ https://www.commoncriteriaportal.org/cc/