Quote:
Originally Posted by JesseK
Essentially, if they gave out how they were deciding to ensure security, someone somewhere would be that much closer to hacking into it.
|
Security through obscurity is an awful, awful way to approach security. Once someone figures out your algorithm (and someone will), then it is game over. If we assume that the attackers are going to figure out how you're securing it anyway, why not let people with good intentions know the algorithm as well so they can point out potential flaws?
The strength of a security system should lie in the attacker not knowing an easily-changed key, not in them not knowing the algorithm.