Security & obscurity

Dafydd Stuttard · Network Security · 2005

A common manoeuvre in discussions about information security is to reject a suggested protective measure as being merely “security through obscurity.” What is implied is that security measures based on “obscurity” do not really amount to security at all, or at least not any kind of security worth bothering with. This article argues that, in the context of protecting an organization's infrastructure at least, security measures thus dismissed are often worthwhile, and can significantly mitigate the security threats facing the organization.

Read the paper · More papers on PaperTik