LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What was security by obscurity, and how does it fare when judged by the Basic Cyber Security Model?

"Nobody knows about my system, so it is safe." Judged by the model there is nothing left of it: no real boundary, no recognition of good or bad actors, no detection of interactions, no notion of a desired environment — it is not a security approach at all.

The historical setting explains why it worked for a while. In the 1960s, computers found their first wide distribution as "minicomputers". Safety came from two circumstances rather than from any design: only a few experts understood the machines at all, and the machines stood in physically secured places. First steps with network connections were being taken, but fully isolated systems were still the order of the day. "Boundaries" rested on expert knowledge or complete isolation.

Even then, bad interaction occurred — and the concept offered little to nothing against a knowing bad actor. That is the fatal property: obscurity protects only against those who do not know, and knowledge spreads in exactly one direction.

Graded against the model, clause by clause:

Model clause Verdict
System boundary None worth the name — expert knowledge or isolation
Good vs bad actors Good actors are recognised as little as bad ones
Good vs bad interactions No detection of interaction at all
Desired environment Unknown

The modern relevance is not historical. Obscurity as the only control is still a live pattern: an unlisted admin URL, an undocumented API, a service that is "internal only" because nobody published the address. Note the difference from legitimate practice — not publishing your internals is fine; relying on their not being known is not. That is exactly Kerckhoffs's principle, which insists a system must stay secure even when everything about it except the key is public.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026