[Full-Disclosure] "security by obscurity"

Georgi Guninski guninski at guninski.com
Mon Dec 9 16:57:35 GMT 2002


Berend-Jan Wever wrote:

> Hmmmm...
> ... isn't hiding your root password security through obscurity ?
> ... isn't hiding your private PGP key security through obscurity ?
> ... isn't 90% of security based on these kinds of obscurity ?


IMHO this is not security by obscurity.
An example for security by obscurity is the following:
I give you an application which does encryption, but I don't tell you how it 
works at all.
The marketing says it is tru$tworthy and unbreakable.




Full-Disclosure is hosted and sponsored by Secunia.