View Single Post
  #134   Spotlight this post!  
Unread 18-04-2008, 09:37
Bongle's Avatar
Bongle Bongle is offline
Registered User
FRC #2702 (REBotics)
Team Role: Mentor
 
Join Date: Feb 2004
Rookie Year: 2002
Location: Waterloo
Posts: 1,069
Bongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond reputeBongle has a reputation beyond repute
Send a message via MSN to Bongle
Re: NEW 2009 Control System Released

Quote:
Originally Posted by JesseK View Post
Essentially, if they gave out how they were deciding to ensure security, someone somewhere would be that much closer to hacking into it.
Security through obscurity is an awful, awful way to approach security. Once someone figures out your algorithm (and someone will), then it is game over. If we assume that the attackers are going to figure out how you're securing it anyway, why not let people with good intentions know the algorithm as well so they can point out potential flaws?

The strength of a security system should lie in the attacker not knowing an easily-changed key, not in them not knowing the algorithm.
Reply With Quote