Security through Obscurity
17
A system relying on security through obscurity may have theoretical or actual security vulnerabilities, but its owners or designers believe that the flaws are not known, and that attackers are unlikely to find them. The basis of STO has always been to run your system on a “need to know” basis. If a person doesn’t know how to do something which could impact system security, then s/he isn’t dangerous. The technique stands in contrast with security by design.
Curated by Yury Chemerkin
Follow
Scooped by Yury Chemerkin onto Security through Obscurity
Scoop.it!

Google will not be prosecuted for Street View Wi-Fi sniffing in Germany | HITBSecNews

Google will not be prosecuted for Street View Wi-Fi sniffing in Germany  | HITBSecNews | Security through Obscurity | Scoop.it
The public prosecutor in Hamburg has decided not to start a criminal investigation into the way Goog..
No comment yet.
Your new post is loading...
Rescooped by Yury Chemerkin from Risk Management and Information Security
Scoop.it!

Understanding The New PCI Vulnerability Management Requirement

Understanding The New PCI Vulnerability Management Requirement | Security through Obscurity | Scoop.it

"After June 30, 2012, the ranking of vulnerabilities becomes a requirement as part of PCI DSS Requirements 6.2 and 6.5.6. This month, we'd like to elaborate some on the "real-world" implications of implementing a risk-ranking assignment into an organization's vulnerability management process."


Via InfoSec
No comment yet.