|
|
|
|
|
by bch
4461 days ago
|
|
It's not about "obscure SSL implementations", it's "alternative implementations", and letting different projects theoretically play off each others strengths and mitigating consumer risk similar to investing in an index or mutual fund rather than all-in with any single entity. Also, there's nothing wrong with security through obscurity, but please don't let that be your only security. |
|
The problem with security through obscurity is that it is not security. Kind of what people mean when they bring it up.. At least in my circles anyway.
It is fine to have security through obscurity but you can't, much like the alternative implementation scenario claim it makes you more secure as a result. Its exactly like when apple claimed they were more secure and couldnt get viruses like their PC counterparts.
That is what I was trying to bring to the conversation when I made my first post. I get the feeling were starting to move off topic / split hairs over words now so I'm going to leave it at that I dont think I can explain myself any further.