Quiz Entry - updated: 2026.09.28
How does security-by-obscurity score against the Basic Cyber Security Model, and how should an architect deal with it?
It fails on every point: no defined system boundary, good and bad actors cannot be distinguished, good and bad interaction cannot be recognised, and the desired environment is unknown. It should not be pursued, but since it usually stems from missing security knowledge, the people involved have to be met where they are.
| BCS criterion | Security-by-obscurity |
|---|---|
| System boundary | Not defined |
| Actors | Good and bad cannot be distinguished |
| Interaction | Good and bad cannot be recognised |
| Environment | Desired environment unknown |
Security-by-obscurity is a poor approach in every respect. When you find it, how you communicate matters: it usually comes from a lack of security knowledge, not from bad intent, so the fix includes explaining and training, not just replacing the mechanism.