Re: Security through Obscurity [was RE: [fw-wiz] Using RDP Port 3389]

From: Elizabeth Zwicky (zwicky_at_greatcircle.com)
Date: 04/28/04

  • Next message: Brian Galdino: "Re: [fw-wiz] iChat A/V and Cisco PIX 501 (6.3)"
    To: Gwendolynn ferch Elydyr <gwen@reptiles.org>
    Date: Wed, 28 Apr 2004 10:02:30 -0700
    
    

    At 1:46 PM -0400 4/27/04, Gwendolynn ferch Elydyr wrote:
    >Speaking of security through obscurity, does anybody happen to have
    >pointers for a pointy-hair friendly explanation of why it may be an
    >adjunct to security, but certainly shouldn't be a primary mechanism?

    With obvious self-interest, I have to say I think the explanation in
    the 2nd edition of Building Internet Firewalls (pp 71-72) is not bad.
    One of the things we do is compare it to day-to-day examples, like
    putting your valuables out of sight when you leave them in the car.
    It's a useful technique, but you still have to lock the car! We also
    discuss why using different ports is not particularly obscure
    (you can check all the ports, or look at traffic, or social engineer
    somebody into telling you the port).

            Elizabeth Zwicky
            zwicky@greatcircle.com

    ----
    zwicky@greatcircle.com
    Newest project: Opal Eleanor Armstrong Zwicky, born March 4, 2004
    Nothing much happened in the last year except a death, a wedding,
    flesh-eating bacteria, a move, and a birth.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Brian Galdino: "Re: [fw-wiz] iChat A/V and Cisco PIX 501 (6.3)"

    Relevant Pages

    • Re: Re: Concepts: Security and Obscurity
      ... last I heard availability had something to do with security. ... Maybe we can all agree that "port obscurity" is a special case of STO. ... BDO Kendalls is a national association of separate partnerships and entities. ... ports are generally available. ...
      (Security-Basics)
    • Re: Concepts: Security and Obscurity
      ... security through the implementation of a layer of obscurity. ... I'm not sure we all agree on a good definition for what "obscurity" ... Many ports advertise themselves ... 2 Market Street Sydney NSW 2000 ...
      (Security-Basics)
    • Re: Concepts: Security and Obscurity
      ... The "obscurity factor" is utterly irrelevant because ... it has no impact what so ever on actual security. ... difference how many times an attacker tries to guess them because they ... nonstandard ports. ...
      (Security-Basics)
    • RE: Concepts: Security and Obscurity
      ... Passwords have their issues - but they are not a obscurity factor. ... 2 Market Street Sydney NSW 2000 ... Subject: Concepts: Security and Obscurity ... Many ports advertise themselves ...
      (Security-Basics)
    • RE: Re: Concepts: Security and Obscurity
      ... ports and the other half on random ports. ... factor of time provided through the addition of an "obscurity" factor ... security from adding a layer of obscurity. ... Hence, reduced risk by ...
      (Security-Basics)