Isn't a password a form of security through obscurity?

后端 未结 8 1301
臣服心动
臣服心动 2021-02-05 03:24

I know that security through obscurity is frowned upon and considered not really secure, but isn\'t a password security through obscurity? It\'s only secure so long as no one f

8条回答
  •  不知归路
    2021-02-05 03:56

    Yes, you are correct and it is a very important realisation you are having.

    Too many people say "security through obscurity" without having any idea of what they mean. You are correct in all that matters is the level of "complexity" of decoding any given implementation. Usernames and passwords are just a complex realisation of it, as they greatly increase the amount of information required to gain access.

    One important thing to keep in mind in any security analysis is the threat model: Who are you worried about, why, and how are you preventing them? What aren't you covering? etc. Keep up the analytical and critical thinking; it will serve you well.

提交回复
热议问题