3 ms·
Obscurity is part of security. I have personally found that by using non-default ports for services that attempts to break in have gone down to zero. For exampl
by joenathan 12y ago
Obscurity is part of security. I have personally found that by using non-default ports for services that attempts to break in have gone down to zero. For example if you leave port 5900 open I guarantee your going to have bots trying to break in day and night. Someone would have to be specifically targeting my network to even find the ports I use(a port scan takes a good amount of time) and the services behind those ports. Of course that's not the only security in place, there are many layers but obscurity plays an important part.
- cefstat 12y agoTotally agree. Obscurity will not save you from a targeted attack but the main problem on the internet now is automated break-in attempts. Obscurity can be very helpful there. Of course I can't help noticing that this is the moral equivalent of having your group attacked by a bear and saving your life by out-running everybody else in the group.
- oneeyedpigeon 12y agoBut if everyone else in your group is running around naked, covered in honey, shouting "come and get me, bear!" and steadfastly refuses to listen to your pleas to stop, I don't think anyone would blame you.
- justincormack 12y agoA port scan of the entire internet takes around 3 minutes if you have enough bandwidth [1] [1] http://blog.erratasec.com/2013/09/masscan-entire-internet-in-3-minutes.html http://blog.erratasec.com/2013/09/masscan-entire-internet-in...
- joenathan 12y agoIf it doesn't DoS my firewall, a port scan like that will be easily detected and blocked. A stealthy port scan takes a good amount of time.
- justincormack 12y agoNot if you interleave the hosts, rather than the ports on each host, as you would.
- frutiger 12y agoJust because you have fewer attempted break-ins doesn't mean your system is more secure. In other words, the only relation between the number of successful break-ins and the number of attempted break-ins is "less than or equal to".
- joenathan 12y agoIf you want to really get down to it, there is no such thing as security, only deterrents, with enough determination and skill a way will be found through all defenses. There are many more script-kiddies out there than real hackers, IMO obscurity successfully deters the script-kiddies in pretty much all cases. If a skilled hacker wants in to your network he will eventually find a way, if even just through social engineering. With a layered approach to security, obscurity, strong passwords, patched systems, log monitoring, encryption, etc... You will successful deter the "hack of opportunity" and even many targeted hacks, leaving you only truly vulnerable to the skilled hacker.