|
|
|
|
|
by belorn
4461 days ago
|
|
Security by diversity means that any extreme rare vulnerability will only hit a few individuals. The trade is that there will be more unique vulnerabilities found. In risk management, having risk spread out is general a favored tactic. Same is true in biology. The chance that remote memory access vulnerability is so rare, that 200 libraries (if equally used) would lower the effected number of people with a factor of almost 200. |
|
Nobody argues security through obscurity doesn't work in some form, we argue that it doesn't make you secure as a matter of fact. Much like using some obscure SSL implementation. It sure does have the net effect of making you less likely to fall victim but that isn't security that is obscurity.