Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

People get this wrong a lot.

Security only through obscurity is no security at all. The argument was generally made in the context of secret, proprietary encryption algorithms. In this context, it was frequently true - security reduced to reverse engineering.

But security isn't a thing. It is a property of a system. And many secure systems strategically employ obscurity for multiple purposes.

Reciting a mantra is a poor substitute for carefully considering your problem domain.



Right, but in the context of this application, there is NO OTHER security except the obscurity of the UUID or it’s hash. The mantra applies quite well here since an attacker could stumble upon a valid hash or UUID and then change the data.


The attacker could stumble upon a valid hash like they could stumble upon a valid password.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: