Hacker News new | ask | show | jobs
by lightedman 3160 days ago
"But obscuring may take away time from securing"

That's because you're looking at the order entirely wrong - you secure then obscure.

2 comments

It is also important to consider the complexity too.

There is no such thing as "Security through unnecessary complexity", only the opposite.

The examples about changing port numbers are great, they are simple configuration changes, when people start wanting to add obscurity "features" they often wander down the path of complexity, inevitably adding vulnerabilities.

> you secure then obscure

pillage THEN burn