GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Alex Gleason (alex@gleasonator.com)'s status on Saturday, 08-Jul-2023 22:59:47 JST Alex Gleason Alex Gleason
    Security through obscurity is not security... except that the only reason it's secure is that it would take 10 million years to brute force it. Is that not security through obscurity?
    In conversation Saturday, 08-Jul-2023 22:59:47 JST from gleasonator.com permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 08-Jul-2023 23:03:53 JST Alex Gleason Alex Gleason
      in reply to
      "Security through obscurity is not security" is a colloquialism. It's practical advice, not philosophical. And would be better written as "weak security is insecure", which is obvious to everybody.
      In conversation Saturday, 08-Jul-2023 23:03:53 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 08-Jul-2023 23:13:05 JST Alex Gleason Alex Gleason
      in reply to
      • errante
      @errante Well, it's like changing /admin to /banana. But the only difference between that and a Bitcoin wallet is low long it takes to brute force it. "Security through obscurity" usually just means it can be brute forced in less than 1 day.
      In conversation Saturday, 08-Jul-2023 23:13:05 JST permalink
    • Embed this notice
      errante (errante@rot.gives)'s status on Saturday, 08-Jul-2023 23:13:06 JST errante errante
      in reply to
      @alex security through obscurity is generally targetted at people using weird stuff ie
      'im on 9front, no one will ever hack me!'
      its the idea that having an uncommon attacl vector makes one secure
      In conversation Saturday, 08-Jul-2023 23:13:06 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 08-Jul-2023 23:22:01 JST Alex Gleason Alex Gleason
      in reply to
      • errante
      @errante Another example is bike locks. Chains can be cut, U-locks can be frozen with canned-air and smashed. If you have an expensive bike it will be a target. But adding 2 locks makes it not usually worth it. Adding 3 locks makes it essentially secure from petty theft, even though a very determined person could still steal it. So is it not worth it to lock your bike? No. Everyone who says "security by obscurity it not security" still locks their bike, because they understand it greatly reduces its chance of being stolen even though it can still be easily broken with enough patience.
      In conversation Saturday, 08-Jul-2023 23:22:01 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Saturday, 08-Jul-2023 23:24:22 JST Alex Gleason Alex Gleason
      in reply to
      • errante
      @errante My main point is that "security by obscurity is not security" is a smug statement, used mostly because it rhymes, and does not help newcomers understand it philosophically. Because ALL security is just levels of obscurity, and GOOD security is just extreme obscurity to the point that breaking it is impractical.
      In conversation Saturday, 08-Jul-2023 23:24:22 JST permalink
    • Embed this notice
      errante (errante@rot.gives)'s status on Saturday, 08-Jul-2023 23:27:12 JST errante errante
      in reply to
      @alex ahh, fair
      In conversation Saturday, 08-Jul-2023 23:27:12 JST permalink
      Alex Gleason likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.