3 ms·
The problem I had with the article was that it said what user accounts he set up, how their security was based, etc. Why!? Don't give away that info in a blog p
by hakaaaaak 14y ago
The problem I had with the article was that it said what user accounts he set up, how their security was based, etc. Why!? Don't give away that info in a blog post! Even if it is something a hacker could easily find out if they wanted, by doing that, you paint a target on your back.
If you are walking past a dark alley in a big city, you don't say, "I am a blue-belt in karate, and I have a wallet with $300 in it." They have a gun, and they'll take that wallet, thank you.
I totally appreciate you putting all those links together, but I would hope that others remember that loose lips sink ships when it comes to security. And from a hacker's perspective, what's the fun in social engineering if someone just blabs it all in a post?
- robomartin 14y agoIf your system can't survive an attack because the attacker learned from a blog post that you are using tool X then perhaps tool X is the problem and not the blog post. Real would-be intruders are not dummies. They have a suite of tests they can run to "x-ray" your system to the extent it is possible and discover vulnerabilities. To some degree it's like encryption code. The safest code has to be open source.
- hakaaaaak 14y ago> The safest code has to be open source. This is a commonly held belief that is not true. I've been doing open source development quite a bit over the last several years and have seen plenty of insecure open source projects that were even less secure than I would see in the private repository of every place I worked. Here's why: * Open source code gets more eyes on it, when it is well-used. But there are loads and loads of projects that are hardly looked at, and they have a greater chance to be used before they are thoroughly vetted. * Those projects were most likely thrown up there by a developer like me who just hacked something up quickly to solve a problem. Once done with the problem, the code stays up there and I just let it atrophy. That consists of 95% of my projects, at least.
- robomartin 14y agoYou misunderstood. I was referring to encryption code. These are open source projects that have to survive the scrutiny of experts. For example, I guarantee you that if I attempted to contribute to an open source encryption code-base without a massive amount of work my submissions would be rejected. This is not my area of expertise. Could I do it? Sure. Nothing is impossible. However, I would have to devote a significant amount of time to fully understanding the state of the art before doing so.