Security through obscurity is not bad
mobeigi.com
Security through obscurity is not bad
1–10 of 228 posts
Re: Security through obscurity is not bad
#2Security ONLY through obscurity is bad (Kerckhoffs's Principle).
Security through obscurity, as an additional layer, is good!
I've been saying this ever since that phrase was coined. A layer or two of obscurity keeps a lot of noise out of logs, reduces alert fatigue and cuts down on storage costs especially if one is using Splunk as their SIEM and makes targeted attacks much easier to detect. I will keep it.
Re: Security through obscurity is not bad
#3Security through obscurity is NOT bad. Security ONLY through obscurity is bad (Kerckhoffs's Principle). Security through obscurity, as an additional layer, is good! I've been saying this ever since that phrase was coined. A layer or two of obscurity keeps a lot of noise out of logs, reduces alert fatigue and cuts down on storage costs especially if one is using Splunk as their SIEM and makes targeted attacks much eas…
Re: Security through obscurity is not bad
#4Security through obscurity is NOT bad. Security ONLY through obscurity is bad (Kerckhoffs's Principle). Security through obscurity, as an additional layer, is good! I've been saying this ever since that phrase was coined. A layer or two of obscurity keeps a lot of noise out of logs, reduces alert fatigue and cuts down on storage costs especially if one is using Splunk as their SIEM and makes targeted attacks much eas…
Couldn't agree more, I have personally benefited from the additional layer and it irks me when people outright claim it has no value.
The argument is that it's much easier to secure proper key material rather than design and config information that can often be leaked accidentally because it's actually directly manipulated by humans (employee onboarding, employee churn etc)
Re: Security through obscurity is not bad
#5Security through obscurity is NOT bad. Security ONLY through obscurity is bad (Kerckhoffs's Principle). Security through obscurity, as an additional layer, is good! I've been saying this ever since that phrase was coined. A layer or two of obscurity keeps a lot of noise out of logs, reduces alert fatigue and cuts down on storage costs especially if one is using Splunk as their SIEM and makes targeted attacks much eas…
Re: Security through obscurity is not bad
#6Re: Security through obscurity is not bad
#7Re: Security through obscurity is not bad
#8”Security including obscurity“ is fine.
Re: Security through obscurity is not bad
#9Earlier quoted context omitted.
Couldn't agree more, I have personally benefited from the additional layer and it irks me when people outright claim it has no value.
The informed claim is not that the obscurity layer has no value. Quite the contrary, it has such a great value that it basically reduces the incentives to have great proper security and thus once the obscurity layer is breached the second line of defense is weaker. The argument is that it's much easier to secure proper key material rather than design and config information that can often be leaked accidentally becaus…
Re: Security through obscurity is not bad
#10“Security through obscurity” has the connotation that it is the obscurity that achieves the security - which is bad. ”Security including obscurity“ is fine.