Log in Sign up
Back to Discover
💻

Security through obscurity

technology Maturity 9-11

You can hide things to keep them safe.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg
You might hide a key in a tire. This helps keep it from being found. But hiding is not enough to stay safe. You still need a good lock. Can you think of a good hiding spot?

55 words

You can hide things to stay safe.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg
This is like a magician using a trick. You might hide a key in a tire. You might hide a note in a book. This makes it hard for others to find.

But hiding is not enough on its own. Experts say you still need a good lock. If someone finds the secret, the safety is gone. It is better to use strong tools.

Some people use hiding to help other tools. This can work well in some cases. It is a way to make things harder to see.

Do you have a good hiding spot?

113 words

You can hide things to stay safe. This is called security through obscurity. It is the practice of hiding how a system works. It is like a magician using a trick. You might hide a note inside a book. You might hide a key on a car tire.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg

Experts say this way is not enough on its own. You should not use it as your only tool. A group called NIST says security should not depend on secrets. If someone finds the secret, the safety is gone. This is like a lock that only works if no one knows it exists.

In 1851, a locksmith named Alfred Charles Hobbs showed a trick. He showed how to pick very good locks. He said bad people already know many secrets. Some computer systems use this method too. They hide details to stop threats. But many of these systems have been broken. This includes some types of phone and radio tools. Hiding things can help other tools. It can make it harder for people to see what you are doing. But it is best to use strong, real locks too.

197 words

Security through obscurity is a way to protect things by hiding them. Instead of using a strong lock, you try to hide the secret. It is like a magician using a trick to hide a card. You might hide a note inside a thick book. You could even hide a car key on a tire.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg
This method tries to make details hard to see. It hopes that if people cannot find a secret, they cannot use it. This is different from using a real lock to stop someone.

This way of working relies on making things hard to understand. If a person cannot see how a system works, they might not try to break it. One way to do this is by changing digital footprints. This means making a computer look like a different kind of device. Another way is to hide sensitive data inside common items. This makes the information look like it does not matter. However, this only works if the secret stays hidden from everyone. If the secret is found, the safety disappears quickly.

History shows us that hiding secrets is very difficult. In 1851, a locksmith named Alfred Charles Hobbs did something bold. He showed the public how to pick very advanced locks. He believed that bad people already knew many secrets. He said that thieves already know more than we can teach them. Later, a rule called Kerckhoffs' doctrine was discussed in books. It says that security should depend on a secret key. The design of the system should not need to stay a secret.

Many experts say that hiding things is not enough. The National Institute of Standards and Technology, or NIST, says this. They believe security should not depend on secret parts. Some systems like GSM or GPRS have tried to use this method. Sadly, many of these digital systems have been broken by experts. Even radio systems like TETRA have faced these problems. Some people even call this a single point of failure. This happens when one secret is the only thing keeping a system safe.

You can think of this like a game of hide-and-seek. If you hide behind a curtain, you might stay safe for a moment. But if someone pulls the curtain, you are found. It is better to have a strong door and a real lock. In the computer world, experts use many different layers of safety. They use things like Moving Target Defense to stay ahead. This helps them protect information better than just hiding it. Using many tools together is much safer than using just one secret.

441 words

Security through obscurity is a specific practice used in security engineering. It involves concealing the details or the internal mechanisms of a system to make it more secure. This approach relies on the principle of hiding things in plain sight. You can compare it to a magician using sleight of hand or a soldier using camouflage. Instead of using physical barriers like heavy locks, this method focuses on obscuring information. The goal is to make the system's workings less visible or harder to comprehend. This reduces the likelihood that someone will perform unauthorized access or manipulation.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg

The mechanism of obscurity works by making the path to a secret difficult to find. One method is disguising sensitive information within very common items. For example, a person might hide a secret note inside a regular book. In the digital world, this might involve spoofing a web browser's version number. Spoofing means changing digital footprints to make a device look like something else. This creates a layer of confusion for potential threats. However, this is not considered a standalone solution. It is most effective when it complements other, stronger security measures.

There are different ways to view the role of obscurity in design. Some people view it as an independent layer of defense. In this view, making things hard to find is a valid tool on its own. However, many experts prefer "security by design" or "open security." These methods focus on building strength into the system itself. There is also a modern approach called Moving Target Defense. This is an advanced version of obscurity used in cybersecurity. It works by constantly changing the system to stay ahead of attackers. Another method is cyber deception, which uses misleading information to trick threats.

History provides important lessons about the limits of hiding secrets. In 1851, a locksmith named Alfred Charles Hobbs challenged the idea of secret designs. He demonstrated to the public how to pick state-of-the-art locks. Hobbs believed that criminals were already very skilled at their jobs. He argued that thieves already knew more than designers could teach them. This event highlighted the danger of relying on secret mechanisms. Later, Kerckhoffs' doctrine was established in the nineteenth century. This doctrine states that a system's security should depend on its key. The design of the system should remain known and not be obscure.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg

Modern standards bodies strongly discourage using obscurity as a single defense. The National Institute of Standards and Technology, or NIST, provides clear guidance. They state that system security should not depend on the secrecy of its components. In the digital world, the Common Weakness Enumeration project labels this mistake as CWE-656. This means relying on obscurity is a recognized weakness in software. Many systems have tried to use this method and failed. This includes components of GSM and GPRS encryption. It also includes GMR encryption and various RFID encryption schemes. Even the Terrestrial Trunked Radio, or TETRA, system has been broken.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg

One common example of this practice is found in anti-malware software. These programs often use secret signatures to flag dangerous files. However, this often leads to a digital arms race. Attackers find new ways to avoid detection by the secret signatures. Then, defenders must create even more complex and secret signatures to catch them. This creates a single point of failure. If the secret method is discovered, the entire defense fails. This cycle shows why relying on hidden details is often a losing battle.

Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key on a car tyre.jpg

Understanding obscurity helps us see how different security fields connect. It relates to the study of steganography, which is hiding messages inside other data. It also connects to software obfuscation, which makes code difficult for humans to read. In the computing history of MIT, the term had a unique meaning. Users of the Incompatible Timesharing System, or ITS, used the term self-mockingly. They used it to describe their own poor documentation and obscure commands. This shows that obscurity can exist in both intentional security and accidental confusion. Whether intentional or not, obscurity changes how people interact with a system.

713 words
🖼️ Images & Media (1)
File:Security through obscurity hiding a key on a car tyre.jpg
Security through obscurity hiding a key...
Up Next
💻
Steganography
Technology
More to explore

What is Nepedia?

A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.