4 ms·
Although, silencing whistleblowers is as weak a strategy as security through obscurity.
by macrolocal 3y ago
Although, silencing whistleblowers is as weak a strategy as security through obscurity.
- deleted 3y ago[deleted]
- phailhaus 3y agoI disagree, it is an extremely strong strategy. You shut them up, they cannot inflict any more damage. The public can speculate what other secrets exist, but they can't know as they would if the whistleblower was kept around. The short-term negative publicity is tiny compared to the fallout if more information was leaked. This is why organizations basically always move to silence: It works.
- macintux 3y agoIt also dissuades other potential whistleblowers.
- macrolocal 3y ago“As weak as” means “as strong as.” But in your scenario, weakness includes failing to adequately limit political or moral liability internally.
- lll-o-lll 3y agoYes exactly. Sunshine is the best disinfectant. Unfortunately, it can take a very long time for the organisation in question to be exposed and then reformed. Just look at the child-abuse within pretty much every organisation that had access to children. However, that doesn’t make the fight fruitless; organisations can be reformed and it’s worth it for society as a whole. We just need much much stronger whistleblower protections.
- staunton 3y agoSecurity through obscurity is how pretty much all cybersecurity security works on practice. There are a few publicly known primitives but organizations trusted with implementing actual security systems will go to great lengths to prevent anyone finding out which of them are used and in what way.
- ungamedplayer 3y agoThis is a naive view of cybersecurity.
- staunton 3y agoWhat's a better and non-naive view? Bonus points if you can explain why it's impossible to develop and sell a link encryptor running OS software.
- ungamedplayer 3y agoWill any explanation do? Sounds like you are limiting your scope to super narrow boundaries.
- staunton 3y agoI honestly don't know what you mean. My question was about your view of how cybersecurity works in practice and what role security by obscurity plays in it.