Security by obscurity IS security. This is in fact how virtually all cryptographic functions and authentication works.
Login to reply
Replies (7)
Nah, Alex. The cryptographic functions aren't secret. Only the private key needs to be kept secret.
there's a difference between a few thousand ports and a qabigllion keys. people are usually talking about the former.
but yes, technically they are of a kind.
"Security through obscurity is NOT bad.
Security ONLY through obscurity is bad (Kerckhoffs's Principle).
Security through obscurity, as an additional layer, is good!"
> virtually all cryptographic functions and authentication
I'm not sure if I got you. These protocols ideally introduce computational complexity, not the cognitive one. How do you define obscurity? The more complex (for understanding) system—the more bugs, which some malicious AI agent will find out at some point.
Security Through Obscurity Is NOT Bad - Mo Beigi
Why security through obscurity still matters: not as your only defence, but as a practical layer that raises attacker cost.
err, no
the meaningful difference is whether de-obscuring the thing breaks one account, or all accounts. if one, that's a credential leak. if all, that's security by obscurity
It's
all the way down.
all the way down.Of course this isn't what people usually mean when they say that though