Earlier quoted context omitted.
If you knew that there was an assassin out there trying to find you and cause you harm, would you consider “I don’t wear a t-shirt with my address on it” to be any form of protection against that assassin? If you want protection against that, you need to focus on better home security, hiring bodyguards, going to the police etc, and you’re better off assuming that the assassin will find your address regardless of whet…
> Put another way: there’s a difference between “I don’t do this thing” and “I rely on not doing this thing for my safety”. That was my point. The fact that some organizations consider AWS account IDs sensitive is independent of whether they rely on it being sensitive or not. I might have taken all precautions against an assassin attack, yet I won't make the assassin's job easier by announcing my PII to them. The fac…
There’s a difference between “making it easier for an attacker” and using it as a security control, even if it’s not the only security control. The point is that even if you don’t go around wearing a shirt with your address on it, that should never factor in to your designs for security. It should never be considered a security control, even a “defense in depth” one.
In fact, your threat model should ideally ask the question “assume someone does walk around with a shirt with my address on it, will I still be safe?” That doesn’t mean you’re actually going to go do it, but if the answer is yes, that’s how you know you’ve done your job.