Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The most simplistic bots just scan specific known ports.

Also, security by obscurity does sometimes work. It's dangerous because you can't depend on it, and often it makes it harder to analyze your security in general. Sometimes, badly implemented security by obscurity can compromise security. In fact, badly implemented security often compromises security, because it is hard to do this stuff. Non-obscure security mechanisms have a distinct advantage -- more eyeballs are looking at them.

So the best policy? I think you should use standard security tools, and then layer simple obscurity over top of that. Keep it minimal so you can make sure it won't mess up some other aspect of your security. It's worth it, just to keep from being the lowest hanging fruit on the tree.

I can't outrun the bear, but I don't have to, because I can outrun you!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: