Meta tags:
Headings (most frequently used words):
obscurity, security, through, contents, history, criticism, in, architecture, vs, technique, see, also, references, external, links,
Text of the page (most frequently used words):
the (77), #security (54), and (30), obscurity (29), #through (19), from (18), archived (12), 2023 (12), retrieved (11), original (11), its (11), this (10), edit (10), system (10), that (10), wikipedia (8), pdf (8), about (7), secrecy (7), information (7), not (7), 2022 (6), page (5), was (5), with (5), links (5), engineering (5), are (5), for (5), design (5), more (5), contents (4), search (4), code (4), may (4), use (4), computer (4), what (4), all (4), standards (4), technology (4), ssrn (4), encryption (4), how (4), used (4), make (4), history (4), hide (4), move (4), sidebar (4), view (3), privacy (3), inc (3), org (3), source (3), open (3), 2018 (3), tetra (3), reliance (3), new (3), app (3), file (3), swire (3), peter (3), january (3), disclosure (3), software (3), when (3), kerckhoffs (3), other (3), alone (3), considered (3), technique (3), include (3), number (3), practice (3), could (3), details (3), control (3), notion (3), cite (3), locks (3), can (3), tools (3), main (3), languages (2), toggle (2), table (2), contact (2), policy (2), available (2), under (2), terms (2), non (2), categories (2), wayback (2), articles (2), short (2), description (2), different (2), wikidata (2), https (2), com (2), they (2), john (2), first (2), external (2), csiac (2), cyber (2), deception (2), daniel (2), miessler (2), valid (2), layer (2), august (2), cops (2), broadcasting (2), paper (2), 2008 (2), cwe (2), 656 (2), national (2), institute (2), guide (2), general (2), 2020 (2), npr (2), iowa (2), 2010 (2), 2006 (2), law (2), journal (2), york (2), isbn (2), building (2), 1883 (2), december (2), 2014 (2), internet (2), web (2), references (2), concealment (2), obfuscation (2), key (2), know (2), see (2), also (2), recent (2), have (2), cybersecurity (2), top (2), camouflage (2), architecture (2), many (2), projects (2), one (2), but (2), flag (2), been (2), components (2), digital (2), discouraged (2), recommended (2), bodies (2), against (2), should (2), depend (2), implementation (2), criticism (2), much (2), there (2), term (2), issue (2), than (2), within (2), generally (2), got (2), community (2), has (2), command (2), patching (2), altmode (2), alt (2), benefits (2), reducing (2), likelihood (2), doctrine (2), them (2), certain (2), access (2), principle (2), such (2), version (2), appearance (2), upload (2), changes (2), read (2), article (2), log (2), create (2), account (2), donate (2), menu (2), add, topic, mobile, cookie, statement, statistics, developers, conduct, legal, safety, contacts, disclaimers, text, additional, apply, using, site, you, agree, registered, trademark, profit, organization, wikimedia, foundation, creative, commons, attribution, sharealike, license, rendered, parsoid, last, edited, october, 2026, utc, hidden, webarchive, template, needing, clarification, september, cryptography, procedures, index, php, title, security_through_obscurity, oldid, 1378513795, obsolescence, robin, miller, june, 2002, linux, bruce, schneier, jay, beale, february, 2007, machine, ain, think, ethan, preston, lofton, publications, economics, shifting, liability, amendment, eric, raymond, cisco, ios, release, 2013, department, homeland, csd, mtd, 2021, www, kpmg, cat, mouse, game, antivirus, evasion, carlo, meijer, wouter, bokslag, jos, wetzels, usenix, scrutiny, midnight, blue, blackhat, usa, breaking, after, decades, shadows, slideshow, mitre, corporation, 2017, 258, server, despite, election, fears, caucuses, will, smartphone, jargon, theory, competitive, reasons, proprietary, government, agencies, 842228, houston, review, 2004, model, helps, network, 531782, telecommunications, high, anderson, ross, 2001, wiley, sons, 471, 38922, 240, dependable, distributed, systems, des, sciences, militaires, cryptographie, militaire, auguste, stross, randall, 2015, times, theater, absurd, selinger, evan, hartzog, woodrow, routledge, companion, philosophy, joseph, pitt, ashley, shew, eds, forthcoming, abstract, 2439866, zwicky, elizabeth, cooper, simon, chapman, brent, 2000, reilly, media, 978, 596, 55188, firewalls, device, talker, full, aacs, controversy, secure, need, morphing, steganography, years, advanced, versions, gained, support, methodology, moving, target, defense, knowledge, built, differs, effectiveness, depends, whether, lives, good, practices, being, independent, tool, operations, stands, contrast, although, real, world, elements, strategies, largest, proponents, commonly, seen, today, anti, malware, typically, occurs, however, attackers, finding, novel, ways, avoid, detection, defenders, coming, increasingly, contrived, secret, signatures, arms, race, single, point, failure, large, telecommunication, cryptosystems, ultimately, broken, these, rfid, schemes, most, recently, terrestrial, trunked, radio, gprs, gmr, gsm, rights, management, nist, recommends, project, lists, common, weakness, enumeration, united, states, reported, declined, share, regarding, sure, relaying, experts, replied, withhold, technical, doesn, protect, caucus, democratic, party, officials, conflicting, stories, origin, fans, say, coined, opposition, users, down, hall, whom, far, culture, referred, self, mockingly, poor, coverage, documentation, commands, attitude, time, tourist, figured, out, trouble, over, urge, because, felt, part, instance, deliberate, noted, allow, running, echoed, typing, set, would, prevent, even, user, later, right, multics, incompatible, timesharing, mit, written, trade, off, between, illusion, military, well, competition, affects, incentives, disclose, further, explanation, needed, loose, lips, sink, ships, accidental, war, were, outweigh, possible, modern, reincarnation, put, forward, nineteenth, century, remaining, obscure, scant, formal, literature, books, anything, example, discussion, openness, nuclear, early, opponent, locksmith, who, 1851, demonstrated, public, state, art, picked, response, concerns, exposing, flaws, vulnerable, criminals, said, rogues, very, keen, their, profession, already, teach, alfred, charles, hobbs, context, protected, extent, difficult, comprehend, concept, hinges, making, workings, less, visible, understandable, thereby, unauthorized, manipulation, concealing, mechanisms, enhance, approach, relies, akin, magician, diverges, traditional, methods, physical, obscuring, characteristics, deter, potential, threats, examples, disguising, sensitive, commonplace, items, like, piece, book, altering, footprints, while, standalone, solution, complement, scenarios, measures, spoofing, browser, sleight, hand, hiding, something, plain, sight, insufficient, only, feature, free, encyclopedia, item, printable, download, print, export, switch, legacy, parser, get, shortened, url, permanent, link, related, here, actions, english, talk, українська, русский, português, polski, norsk, bokmål, nederlands, italiano, magyar, עברית, français, español, ελληνικά, deutsch, čeština, català, العربية, personal, special, pages, portal, learn, help, contribute, random, current, events, navigation, jump, content,
Text of the page (random words):
security through obscurity wikipedia jump to content main menu main menu move to sidebar hide navigation main page contents current events random article about wikipedia contact us contribute help learn to edit community portal recent changes upload file special pages search search appearance donate create account log in personal tools donate create account log in contents move to sidebar hide top 1 history 2 criticism 3 obscurity in architecture vs technique 4 see also 5 references 6 external links toggle the table of contents security through obscurity 17 languages العربية català čeština deutsch ελληνικά español français עברית magyar italiano nederlands norsk bokmål polski português русский українська 中文 edit links article talk english read edit view history tools tools move to sidebar hide actions read edit view history general what links here related changes upload file permanent link page information cite this page get shortened url switch to legacy parser print export download as pdf printable version in other projects wikidata item appearance move to sidebar hide from wikipedia the free encyclopedia reliance on design or implementation secrecy for security security through obscurity is generally considered insufficient and not to be used as the only security feature of a system in security engineering security through obscurity is the practice of concealing the details or mechanisms of a system to enhance its security this approach relies on the principle of hiding something in plain sight akin to a magician s sleight of hand or the use of camouflage it diverges from traditional security methods such as physical locks and is more about obscuring information or characteristics to deter potential threats examples of this practice include disguising sensitive information within commonplace items like a piece of paper in a book or altering digital footprints such as spoofing a web browser s version number while not a standalone solution security through obscurity can complement other security measures in certain scenarios 1 obscurity in the context of security engineering is the notion that information can be protected to a certain extent when it is difficult to access or comprehend this concept hinges on the principle of making the details or workings of a system less visible or understandable thereby reducing the likelihood of unauthorized access or manipulation 2 security by obscurity alone is discouraged and not recommended by standards bodies history edit an early opponent of security through obscurity was the locksmith alfred charles hobbs who in 1851 demonstrated to the public how state of the art locks could be picked in response to concerns that exposing security flaws in the design of locks could make them more vulnerable to criminals he said rogues are very keen in their profession and know already much more than we can teach them 3 there is scant formal literature on the issue of security through obscurity books on security engineering cite kerckhoffs doctrine from 1883 if they cite anything at all for example in a discussion about secrecy and openness in nuclear command and control t he benefits of reducing the likelihood of an accidental war were considered to outweigh the possible benefits of secrecy this is a modern reincarnation of kerckhoffs doctrine first put forward in the nineteenth century that the security of a system should depend on its key not on its design remaining obscure 4 5 peter swire has written about the trade off between the notion that security through obscurity is an illusion and the military notion that loose lips sink ships 6 as well as on how competition affects the incentives to disclose 7 further explanation needed there are conflicting stories about the origin of this term fans of mit s incompatible timesharing system its say it was coined in opposition to multics users down the hall for whom security was far more an issue than on its within the its culture the term referred self mockingly to the poor coverage of the documentation and obscurity of many commands and to the attitude that by the time a tourist figured out how to make trouble he d generally got over the urge to make it because he felt part of the community one instance of deliberate security through obscurity on its has been noted the command to allow patching the running its system altmode altmode control r echoed as d typing alt alt control d set a flag that would prevent patching the system even if the user later got it right 8 in january 2020 npr reported that democratic party officials in iowa declined to share information regarding the security of its caucus app to make sure we are not relaying information that could be used against us cybersecurity experts replied that to withhold the technical details of its app doesn t do much to protect the system 9 criticism edit security by obscurity alone is discouraged and not recommended by standards bodies the national institute of standards and technology nist in the united states recommends against this practice system security should not depend on the secrecy of the implementation or its components 10 the common weakness enumeration project lists reliance on security through obscurity as cwe 656 11 a large number of telecommunication and digital rights management cryptosystems use security through obscurity but have ultimately been broken these include components of gsm gmr encryption gprs encryption a number of rfid encryption schemes and most recently terrestrial trunked radio tetra 12 one of the largest proponents of security through obscurity commonly seen today is anti malware software what typically occurs with this single point of failure however is an arms race of attackers finding novel ways to avoid detection and defenders coming up with increasingly contrived but secret signatures to flag on 13 the technique stands in contrast with security by design and open security although many real world projects include elements of all strategies obscurity in architecture vs technique edit knowledge of how the system is built differs from concealment and camouflage the effectiveness of obscurity in operations security depends on whether the obscurity lives on top of other good security practices or if it is being used alone 14 when used as an independent layer obscurity is considered a valid security tool 15 in recent years more advanced versions of security through obscurity have gained support as a methodology in cybersecurity through moving target defense and cyber deception 16 see also edit steganography code morphing need to know obfuscation software secure by design aacs encryption key controversy full disclosure computer security code talker obfuscation concealment device references edit zwicky elizabeth d cooper simon chapman d brent 2000 06 26 building internet firewalls internet and web security o reilly media inc isbn 978 0 596 55188 9 selinger evan and hartzog woodrow obscurity and privacy may 21 2014 routledge companion to philosophy of technology joseph pitt ashley shew eds 2014 forthcoming available at ssrn https ssrn com abstract 2439866 stross randall 17 december 2006 theater of the absurd at the t s a the new york times archived from the original on 8 december 2022 retrieved 5 may 2015 auguste kerckhoffs january 1883 la cryptographie militaire pdf journal des sciences militaires ix 5 38 anderson ross 2001 security engineering a guide to building dependable distributed systems new york ny john wiley sons inc p 240 isbn 0 471 38922 6 swire peter p 2004 a model for when disclosure helps security what is different about computer and network security journal on telecommunications and high technology law 2 ssrn 531782 swire peter p january 2006 a theory of disclosure for security and competitive reasons open source proprietary software and government agencies houston law review 42 ssrn 842228 security through obscurity the jargon file archived from the original on 2010 03 29 retrieved 2010 01 29 despite election security fears iowa caucuses will use new smartphone app npr org archived from the original on 2022 12 23 retrieved 2020 02 06 guide to general server security pdf 258 kb national institute of standards and technology 2008 07 01 archived pdf from the original on 2017 08 09 cwe 656 reliance on security through obscurity the mitre corporation 2008 01 18 archived from the original on 2023 09 28 retrieved 2023 09 28 midnight blue august 2023 all cops are broadcasting breaking tetra after decades in the shadows slideshow pdf blackhat usa 2023 archived pdf from the original on 2023 08 11 retrieved 2023 08 11 carlo meijer wouter bokslag jos wetzels august 2023 all cops are broadcasting tetra under scrutiny paper pdf usenix security 2023 archived pdf from the original on 2023 08 11 retrieved 2023 08 11 kpmg may 2022 the cat and mouse game of antivirus evasion archived from the original on 2023 08 28 retrieved 2023 08 28 obscurity is a valid security layer daniel miessler daniel miessler archived from the original on 2022 12 08 retrieved 2018 06 20 cyber deception csiac www csiac org archived from the original on 2021 04 20 retrieved 2018 06 20 csd mtd department of homeland security 2013 06 25 archived from the original on 2022 12 08 retrieved 2018 06 20 external links edit eric raymond on cisco s ios source code release v open source computer security publications information economics shifting liability and the first amendment by ethan m preston and john lofton security through obscurity ain t what they think it is at the wayback machine archived february 2 2007 by jay beale secrecy security and obscurity the non security of secrecy by bruce schneier security through obsolescence robin miller linux com june 6 2002 retrieved from https en wikipedia org w index php title security_through_obscurity oldid 1378513795 categories computer security procedures cryptography secrecy security engineering hidden categories articles with short description short description is different from wikidata wikipedia articles needing clarification from september 2022 webarchive template wayback links this page was last edited on 4 october 2026 at 21 04 utc page was rendered with parsoid text is available under the creative commons attribution sharealike 4 0 license additional terms may apply by using this site you agree to the terms of use and privacy policy wikipedia is a registered trademark of the wikimedia foundation inc a non profit organization privacy policy about wikipedia disclaimers contact wikipedia legal safety contacts code of conduct developers statistics cookie statement mobile view search search toggle the table of contents security through obscurity 17 languages add topic
|