 DanielPremium,MVM join:2000-06-26 San Francisco, CA 1 edit | reply to Cabal
Re: Security and Obscurity: Changing Daemon Ports said by Cabal:I will disagree with you on your terminology. You haven't in any way made your service "more secure," you've only extended the time it takes to be compromised. I've "extended the time it takes to be compromised" but I haven't increased my security? What, then, would you call increasing security as opposed to just making it take longer for people to compromise you?
Putting camouflage on tanks doesn't increase their "security" then either, right? It just takes longer for them to be targeted on the battle field -- which keeps them alive longer. But that's not really security, right?
I have actually increased my security precisely because I've made it less likely that someone would compromise me. It's less likely because attackers VERY rarely waste time sending their exploits to random non-standard ports when they launch their attacks. It's just not economical for them, which equates to more security for those who do move their listeners. -- dmiessler.com -- grep understanding knowledge |