Hacker News new | ask | show | jobs
by marcosdumay 1338 days ago
Exactly. "Security by obscurity" is a badly defined term that security people use to name the practices that bring too little benefit for their implementation cost.

It's derogatory by definition, so it can not be underrated. One can disagree about the evaluation of some specific practice, but the people that insist on doing that usually have a horrible track record and even completely wrong mental models (like using the Swiss cheese model for security, when it's only useful against Nature, not humans).