3 ms·
> Obscurity is not security. So ASLR [1] is not a security control? I guess you are pretty alone with this opinion. [1] https://en.wikipedia.org/wiki/Address_
by kbrkbr 5mo ago
> Obscurity is not security.
So ASLR [1] is not a security control? I guess you are pretty alone with this opinion.
[1] https://en.wikipedia.org/wiki/Address_space_layout_randomization https://en.wikipedia.org/wiki/Address_space_layout_randomiza...
- msm_ 5mo agoNo this is not what GP said, and I don't get how you reached this conclusion. This is like saying that AES is security through obscurity because it relies on key being secret. See [1] (linked in the OP) to understand the difference better. I am pretty sure everyone who works in security agrees that obscurity is not security. [1] https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- minitech 5mo agoASLR is (still[1]) not security by obscurity. [1] https://news.ycombinator.com/item?id=43408079 https://news.ycombinator.com/item?id=43408079
- bigstrat2003 5mo agoASLR is, by definition, security by obscurity. The entire purpose of it is to make it so that it's hard to find the memory which is in use.
- sixtiethutopia 5mo agoThat's not what security through obscurity means. Security through obscurity has a specific meaning, it doesn't just mean to gain security by hiding anything it means to attempt to gain security by hiding how a system works. ASLR is a well understood system that exploit writers know to expect and thus ASLR is not security through obscurity.
- deleted 5mo ago[deleted]
- imtringued 5mo agoThe point of ASLR is that even if you fully understand how it works, this won't make it easier to bypass the protections of ASLR, since the primary way ASLR works is through dynamic adaptation. This turns it into a probabilistic security technique where there is always a chance that an attack goes through. Security through obscurity in this case would be to roll your own ASLR implementation with a different randomization strategy.
- grayhatter 5mo agono because it's still possible to find the data using standard techniques, it doesn't count as obsecurity it's still possible. I.e. just because you* don't know where something is, doesn't mean it's using obsecurity to hide. The reason is important, because words mean things: If you say, knowledge of some secret is security though obsecurity. That means passwords are security though obsecurity. *: that may or may not be available to the attacker. it other words, just because a secret exists, doesn't put that secret into the 'obsecurity' category.
- staticassertion 5mo agoNo, because ASLR uses a secret.