Hacker News new | ask | show | jobs
by onion2k 4232 days ago
I still fully believe that any long-term security measure requiring secrecy is bound to fail and/or be ineffective.

A security system needs to be effective against attack. That's simple and obvious. But beyond that I think there's a very big difference between 'requiring secrecy' for the effectiveness of a system and wanting to keep something as secret as reasonably possible. Hypothetically, it could be that people attacking a system would harm civilians while capturing attackers in their planning stage (eg while they're investigating the system) would prevent danger to the public. If that was the case then keeping the system secret might well be worthwhile.

You shouldn't immediately assume that an attempt to keep something secret is 'security through obscurity'. It might be obscurity with no regard to increasing security.