5 ms·
> to a large extent, it's directly because of hardware based privacy features. First, this is 100% false. Second, security through obscurity is almost universa
by nkmskdmfodf 2y ago
> to a large extent, it's directly because of hardware based privacy features.
First, this is 100% false. Second, security through obscurity is almost universally discouraged and considered bad practice.
- ghostpepper 2y agoThis is a common saying but in reality, security through obscurity is widely deployed and often effective. More pragmatic advice would be to not rely solely on security through obscurity, but rather to practice defence in depth.
- nkmskdmfodf 2y agoSecurity by insecurity is also 'widely deployed and often effective'.
- bilekas 2y agoObfuscation is not security.. So there can't be "security through obscurity". Widely deployed doesn't mean it's a positive action, and effective ? It just can't be as it's not a security. People really need to pay more attention to these things, or else we DO get nonsense rolled out as "effective".
- MediumOwl 2y ago> Second, security through obscurity is almost universally discouraged and considered bad practice. This is stupid advice that is mindlessly repeated. Security by obscurity only is bad, sure. Adding obscurity to other layers of security is good. Edit: formatting
- meibo 2y agoNo, that's just plain wrong in this case. It makes proper security research much harder and what's going on with your hardware less obvious.
- nkmskdmfodf 2y agoNah, you have no idea what you're talking about.
- _yb2s 2y agoSecurity though obscurity is highly effective. Think of some common sense physical analogies: a hidden underground bunker is much less likely to be robbed than a safe full of valuables in your front yard. A bicycle buried deeply in bushes is less likely to be stolen than one locked to a bike rack. Without obscurity it is straightforward to know exactly what resources will be required to break something- you can look for a flaw that makes it easy and/or calculate exactly what is required for enough brute force. When you add the element of well executed obscurity on top of an also strong system, it becomes nearly impossible to even identify that there is something to attack, or to even start to form a plan to do so. Combining both approaches is best, but in most cases I think simple obscurity is more powerful and requires less resources than non obscure strength based security. I’ve managed public servers that stayed uncompromised without security updates for a decade or longer using obscurity: an archaic old Unix OS of some type that does not respond to pings or other queries, runs services on non-standard ports, and blocks routes to hosts that even attempt scanning the standard ports will not be compromised. Obviously also using a secure OS with updates on top of these techniques is better overall.
- mu53 2y agoI think the scenario that security through obscurity fails is when the end user is reliant on guarantees that don't exist. For example Intel's Management Engine, it was obscured very well. It wasn't found for years. Eventually people did find it, and you can't help but wonder how long it took for bad actors with deep pockets to find it. Its this obscured cubby hole in your CPU, but if someone could exploit it, it would be really difficult to find out because of intel's secrecy on top of the feature.
- _yb2s 2y agoIt seems like people are really talking about different things with obscurity. Some are referring to badly designed weak systems, where secrecy and marketing hype is used to attempt to conceal the flaws. Others, like my comment above, are talking about systems carefully engineered to have no predictable or identifiable attack surfaces- things like OpenBSDs memory allocation randomization, or the ancient method of simply hiding physical valuable things well and never mentioning them to anyone. I’ve found when it is impossible for an external bad actor to even tell what OS and services my server is running- or in some cases to even positively confirm that it really exists- they can’t really even begin to form a plan to compromise it.
- Tagbert 2y agoWhere did you come up with “ security through obscurity ” in that previous commment? It said nothing about using an obscurity measure. He was talking about hardware based privacy features.
- kvakkefly 2y agoWhat do you mean by considered bad practice? By whom? I would think this is one of the reasons that my Macs since 2008 have just worked without any HW problems.