Printer Friendly
Dictionary, Encyclopedia and Thesaurus - The Free Dictionary
3,895,516,848 visitors served.
forum Join the Word of the Day Mailing List For webmasters
?
Dictionary/
thesaurus
Medical
dictionary
Legal
dictionary
Financial
dictionary
Acronyms
 
Idioms
Encyclopedia
Wikipedia
encyclopedia
?

security through obscurity
(redirected from Security through obsurity)

   Also found in: Wikipedia 0.01 sec.
(security)security through obscurity - Or "security by obscurity". A term applied by hackers to most operating system vendors' favourite way of coping with security holes - namely, ignoring them, documenting neither any known holes nor the underlying security algorithms, trusting that nobody will find out about them and that people who do find out about them won't exploit them. This never works for long and occasionally sets the world up for debacles like the RTM worm of 1988 (see Great Worm), but once the brief moments of panic created by such events subside most vendors are all too willing to turn over and go back to sleep. After all, actually fixing the bugs would siphon off the resources needed to implement the next user-interface frill on marketing's wish list - and besides, if they started fixing security bugs customers might begin to *expect* it and imagine that their warranties of merchantability gave them some sort of rights.

Historical note: There are conflicting stories about the origin of this term. It has been claimed that it was first used in the Usenet newsgroup in news:comp.sys.apollo during a campaign to get HP/Apollo to fix security problems in its Unix-clone Aegis/DomainOS (they didn't change a thing). ITS fans, on the other hand, say it was coined years earlier in opposition to the incredibly paranoid Multics people down the hall, for whom security was everything. In the ITS culture it referred to (1) the fact that by the time a tourist figured out how to make trouble he'd generally got over the urge to make it, because he felt part of the community; and (2) (self-mockingly) the poor coverage of the documentation and obscurity of many commands. One instance of *deliberate* security through obscurity is recorded; the command to allow patching the running ITS system (altmode altmode control-R) echoed as $$^D. If you actually typed alt alt ^D, that set a flag that would prevent patching the system even if you later got it right.


Want to thank TFD for its existence? Tell a friend about us, add a link to this page, add the site to iGoogle, or visit the webmaster's page for free fun content.
?Page tools
Printer friendly
Cite / link
Feedback
Mentioned in?   Encyclopedia browser?   Full browser?
No references found
 
 
Security Techniques Advisory Group
Security Technology Deployment Office
Security Technology Group
Security Technology Integration Program
Security Technology Unit
Security Termination Statement
Security Test & Evaluation
Security Test and Analysis Tool
Security Test Automation
Security Test Plan
Security Testing
Security Testing - Compliance Testing
Security Testing - Data Backup
Security Testing Procedural Review
Security Threat Analysis and Research
Security Threat Assessment
Security Threat Avoidance Technology
Security Threat Group
Security Threat Intelligence Unit
Security Threat Mitigation
Security Through Interaction Modeling
Security through obfuscation
Security through obscurity
Security through obscurity
Security through obsolescence
Security through obsurity
Security token
Security Token Service
Security tokens
Security Tools Distribution
Security Tracking and Authorization Request System
Security Tracking of Office Property
Security Trader Association
Security Traders Association
Security Traders Association
Security Traders Association
Security Traders Association of Los Angeles, Inc.
Security Traders Association of New York
Security Trained and Ready
Security Training, Assistance, Assessment Team
Security Transfer Agents Medallion Program Inc
Security Transfer Agents Medallion Program Inc.
Security Transformations Application Service Element
Security Update-Validation Program
Security UserID Definition System
Security Validation Description Language
Security Valuation
security valuation model
Security Valuations
Security Variable Data Printing
Security Version
Security Violation Report
 
Encyclopedia
?

Terms of Use | Privacy policy | Feedback | Advertise with Us | Copyright © 2012 Farlex, Inc.
Disclaimer
All content on this website, including dictionary, thesaurus, literature, geography, and other reference data is for informational purposes only. This information should not be considered complete, up to date, and is not intended to be used in place of a visit, consultation, or advice of a legal, medical, or any other professional.