Re: security through obscurity (was: Re: remove apache os banner

From: Darkk (darkkeclipse@subdimension.com)
Date: 06/07/02


From: "Darkk" <darkkeclipse@subdimension.com>
To: "John Daniele" <johnd@tsintel.com>
Date: Sat, 8 Jun 2002 05:34:17 +0900


>
> I'm absolutely not advocating that anyone implement security through
> obscurity, but would have to agree that some degree of obscurity can slow
> down some attacks.. however, it should be the VERY, VERY, VERY last thing
> on your mind, and NEVER be relied upon as a means of protecting a network,
> application, building or anything.
>

Absolutely agreed.
You put in a single paragraph, what I was unable to summarise so well, in
several.
Banner munging and StO *is* a useful measure... but should be the last item
on the list.

Regards,
D



Relevant Pages

  • RE: Filtering email headers generated from internal network (Sensible?)
    ... IMO there's a balance between sec through obscurity ... Generally speaking sec through obscurity implies (to ... safe, you're using STO. ... kinda Security by obscurity. ...
    (Pen-Test)
  • RE: Concepts: Security and Obscurity
    ... resources are limited and thus there is a cost to life. ... It is not obscurity in the manner being ... more you spend on security the less of an advantage is gained. ... It also ignores the requirements of a control function. ...
    (Security-Basics)
  • RE: Re: Concepts: Security and Obscurity
    ... so long as you understand that the server location and port number ... security in the slightest." ... Beale's assertion that "Obscurity Potentially Slows Down the Attacker". ... BDO Kendalls is a national association of separate partnerships and entities. ...
    (Security-Basics)
  • Re: NAT external/Public IP
    ... I remember working for an ISP a long while back that was threatened to be disconnected from the Internet if they did not stop routing the 10.x range in their BGP tables. ... Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. ... Why not Security by Design plus Security by Obscurity? ...
    (Security-Basics)
  • RE: Concepts: Security and Obscurity
    ... Subject: Concepts: Security and Obscurity ... I have at no point claimed absolute security measures or cost ... It also ignores the requirements of a control function. ...
    (Security-Basics)