LOGBOOK

HELP

Quiz Entry - updated: 2026.09.28

What is the basic idea of security-by-obscurity, and what did its failure lead to?

"Nobody knows about my system, so it is secure": the system boundary is the "boundary of those in the know". Once networks spread, bad interaction appeared and hiding proved insufficient, which led to network perimeter security, access control through authentication and authorisation, and system hardening.

It is a very old model from the first steps with network connections, when there were few experts. The assumption: if nobody, or only a tiny circle of initiated people, knows how the system works, it is safe.

With networking came the first appearance of bad interaction: a system had capabilities to interact that nobody had noticed, and someone found them. The lesson was that hiding is not a security concept. The models that followed:

  • network perimeter security,
  • access control via authentication and authorisation (AAA),
  • further system-based measures such as hardening and the minimal principle.

From Quiz: CSARCH / Security-by-Isolation and Security-by-Obscurity | Updated: Sep 28, 2026