Hacker News new | ask | show | jobs
by GoblinSlayer 2008 days ago
All security eventually relies on obscurity, it's a bad idea to disclose your security practices. Use hunter2 as password for junk sites.
3 comments

From a humor point of view that would be a good idea, something like "dontbothertryingtostealmyaccount".

I also agree somewhat about obscurity. Notice that I haven't said what password manager I use, or where I store it. The fact that I use a password manager I don't consider sensitive though.

By that same logic, use disposable email addresses and the password doesn’t matter? I mean, this kind of thing only holds up while you don’t care to enter any data about yourself and re-visit the site later. Those who need to be anonymous can provide junk info to junk sites, sure, but for everything else, there’s email and 2FA TOTP codes and password managers for a reason... largely because OAuth and FIDO2 aren’t universal yet I suppose ;-)
Can you elaborate on why all security will eventually rely on obscurity?
It's jokingly called Fleming's cryptanalysis: if there's a secret key, you just send James Bond to steal it.
The only type of obscurity that would protect me against that type of attack is if I myself am entirely obscure. By having one the most valuable accounts in a video game, I've already given up on that.