logoalt Hacker News

mobeigiyesterday at 3:35 PM1 replyview on HN

Couldn't agree more, I have personally benefited from the additional layer and it irks me when people outright claim it has no value.


Replies

ithkuilyesterday at 3:53 PM

The informed claim is not that the obscurity layer has no value. Quite the contrary, it has such a great value that it basically reduces the incentives to have great proper security and thus once the obscurity layer is breached the second line of defense is weaker.

The argument is that it's much easier to secure proper key material rather than design and config information that can often be leaked accidentally because it's actually directly manipulated by humans (employee onboarding, employee churn etc)

show 1 reply