Hacker News new | ask | show | jobs
by gowld 2102 days ago
Hmm, maybe security via obscurity is a bad idea after all.
1 comments

:-)

Arguably, it's a negative.

Searching Ghodan for ssh server that are not on port 22 probably gives you back a venn diagram containing circles for "people who thing security by obscurity works" and "people who think their stuff is important enough to 'hide' by configuring non standard port numbers".

The intersection there probably has some interesting low hanging fruit in it...

(There's a third circle in that venn diagram which I sometimes sit in, labeled "people who change port numbers to keep log file noise lower", which wile maybe being a valid choice, also opens you up to being thought of as "interesting possibly low hanging fruit" by the sort of people who thing those things.)