Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A knee-jerk aversion to anything halfway adjacent to "security by obscurity" is flawed, but this reaction to that aversion is also flawed.

Instead of trying to suggest "security by obscurity is fine, actually, and don't worry about it", it's time for us to just stop being pithy and start being precise: your cryptosystem should be secure even if your adversaries understand everything about it. If that is true, then you can (and, in the real world, almost certainly should) add defense in depth by adding layers of obscurity, but not before.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: