The article discusses the concept of security by obscurity, which is often considered a bad practice in the information security field. However, the author argues that it can be a useful additional layer of defense when used in conjunction with other security measures. The article provides examples of how changing default ports and using code obfuscation can reduce the likelihood of a successful attack. The author concludes that security by obscurity is not a replacement for traditional security measures, but it can be a low-cost and effective way to reduce risk.