Full Disclosure mailing list archives

Re: "security by obscurity"


From: Georgi Guninski <guninski () guninski com>
Date: Mon, 09 Dec 2002 18:57:35 +0200

Berend-Jan Wever wrote:

Hmmmm...
... isn't hiding your root password security through obscurity ?
... isn't hiding your private PGP key security through obscurity ?
... isn't 90% of security based on these kinds of obscurity ?


IMHO this is not security by obscurity.
An example for security by obscurity is the following:
I give you an application which does encryption, but I don't tell you how it works at all.
The marketing says it is tru$tworthy and unbreakable.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: