I don't think any competent security researcher has anything positive to say about "security through obscurity"
at best this is lawyer position
I don't think any competent security researcher has anything positive to say about "security through obscurity"
at best this is lawyer position
Obscurity is totally underrated. Attacker resources are limited.
Further more you can also reveal position of the attacker and counterfire.
If someone with 1000 tanks attacks, it's a battle you would not have won anyway.
Sure it's not a security measure as such, but it's still a worthwile component to the overall defense system.
Are you familiar with the Swiss cheese model of risk management[0]? Obscurity is just another slice of Swiss cheese. It's not your only security measure. You still use all the other measures.
This isn't about security of the same kind as authentication/encryption etc where security by obscurity is a bad idea. This is an effort where obscurity is almost the only idea there is, and where even a marginal increase in difficulty for tampering/inspecting/exploiting is well worth it.
They apply to different threats and different contexts. When you have code running in the attackers' system, in normal privilege so they can pick it apart, then obscurity is basically all you have. So the only question to answer is: do you want a quick form of security through obscurity, or do you not? If it delivers tangible benefits that outweigh the costs, then why would you not?
What one is aiming for here is just slowing an annoying down an attacker. Because it's the best you can do.
Some people find cracking them interesting and fun.
The goal is not perfect security in all situations for all products. The goal is to make the effort required for your particular product excessive compared to the payoff.
Take the PS5 for example. It has execute-only memory. Even if you find a bug, how do you exploit it if you can't read the executable text of your ROP/JOP target?