Hacker News new | ask | show | jobs
by danellis 3754 days ago
If you're not comfortable answering that, perhaps it's a sign that you should be keeping them somewhere more secure.
1 comments

I don't agree with that. It could be as secure as could be, but I'd still be pointing at the keys and that's information that no outsider needs to have. Why give that up? It saves them from having to look for the keys, they can now set up a targeted attack on obtaining the keys because their location is already known and that's half the battle.
Yes, not knowing where to even start the attack does make it more difficult to complete an attack. But, there is no way it could make it easier. I mean adding plastic wrap around your safe does technically make it more difficult to break into, but the issue comes where you come to rely on it. My safe is 100% uncrackable, as long as it doesn't get wet, thanks plastic wrap.
That's not the question though. The question is 'where do you keep the key to your safe'?
Hopefully it's more like "what kind of safe do you keep the keys to your other safe in?"

I think the point is in relying on something that is fundamentally secure, not secure because it is obscure. If I print my private key on a piece of paper and pin it up by my desk that's something I shouldn't tell people, but if I have it locked in an unspecified safe deposit box, there isn't much harm in describing what the deposit box is made out of.

It does make you less secure, but a good security plan starts from assuming your adversary knew all that sort of thing in the first place.