news.volyx.in

Security by obscurity is underrated (utkusen.com)

939 points by goranmoomin · 2209 days ago · 510 comments on HN

Article summary

The article discusses the concept of security by obscurity, which is often considered a bad practice in the information security field. However, the author argues that it can be a useful additional layer of defense when used in conjunction with other security measures. The article provides examples of how changing default ports and using code obfuscation can reduce the likelihood of a successful attack. The author concludes that security by obscurity is not a replacement for traditional security measures, but it can be a low-cost and effective way to reduce risk.

Main themes

  • security by obscurity
  • defense in depth
  • port knocking
  • code obfuscation
  • security trade-offs
  • risk management

What commenters say

  • Security by obscurity can be a useful additional layer of defense when used in conjunction with other security measures.
  • Port knocking is not a reliable security measure and can be easily circumvented by determined attackers.
  • Using obscurity as a security measure can add complexity and inconvenience for legitimate users, potentially outweighing its benefits.
  • In some cases, such as when a dedicated attacker is expected, obscurity can be used to delay an attack and make it more difficult to succeed.
  • Traditional security measures, such as encryption and secure protocols, are more effective and reliable than security by obscurity.
  • Security by obscurity can be effective in reducing the noise from opportunistic attacks, but it is not a substitute for proper security measures.
  • The use of obscurity as a security measure is not a zero-sum game, and it can be used in conjunction with other security measures to improve overall security.