logoalt Hacker News

kbrkbryesterday at 5:04 PM4 repliesview on HN

> Obscurity is not security.

So ASLR [1] is not a security control? I guess you are pretty alone with this opinion.

[1] https://en.wikipedia.org/wiki/Address_space_layout_randomiza...


Replies

msm_yesterday at 5:18 PM

No this is not what GP said, and I don't get how you reached this conclusion. This is like saying that AES is security through obscurity because it relies on key being secret. See [1] (linked in the OP) to understand the difference better.

I am pretty sure everyone who works in security agrees that obscurity is not security.

[1] https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle

show 1 reply
minitechyesterday at 5:21 PM

ASLR is (still[1]) not security by obscurity.

[1] https://news.ycombinator.com/item?id=43408079

show 1 reply
staticassertionyesterday at 7:29 PM

No, because ASLR uses a secret.