Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This argument is a strawman. Does OP have a real example of someone arguing that obscurity as a layer on top of good security is a bad thing?


I hear people call moving the ssh port "security by obscurity" all the time. For instance:

http://serverfault.com/questions/189282/why-change-default-s...

http://serverfault.com/questions/316516/does-changing-defaul...


Yeah go look on security stackexchange and you'll see it quite a bit, people just cargo cult the idea of obscurity == bad and don't consider the points made in OP's article


I don't think it's that bad, but if you believe that security through obscurity is not secure, and you are using it with something that is secure, then it is in practice adding nothing, and not worth it.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: