|
|
|
|
|
by grayhatter
1 hour ago
|
|
> I don't know what methods where used to find these exploits but I am starting to think security through obscurity might not be a bad thing in this day and age, where someone can just let bots loose on your codebase. I'd love to hear why you think obscurity is bad, if you now think maybe it's good in the LLM age? I'd also be interested if you could describe exactly what or how you think security through obscurity works, or doesn't? I've been thinking a lot about how to better teach this concept, so I'm looking to understand exactly how everyone thinks/understands how it currently works, or should work, or what it should do. I don't care about the "correct" answer, (I have ddg too :P) I'm interested in general expectations from SWE's that I might teach at work, instead of opinions of security eng speaking about theory. |
|
In the case of FOSS software, it is generally recognized that the small advantage of keeping the source secret is far outweighted by the contributions and vuln reports you get if you publish the source.