Re: DNS Names for external services

[email protected]
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Wed, Apr 14, 2010 at 11:57:48AM +0100, John Morrison wrote:
> I have to agree with the view that obfuscation/obscurity is not the
> way to go. It increases the difficulty of use and, in this case,
> provides very little benefit.

In this case, yes, it provides very little benefit.  However, I think the 
"no security through obscurity" meme is sometimes carried too far.  In 
Schneier's article (referenced below) he says:

    "Just because security does not require that something be kept secret, it
    doesn't mean that it is automatically smart to publicize it."

Body armor with effective camouflage is preferable to body armor in day-glo
colors.

> 
> See
>         "Why Security-Through-Obscurity Won't Work"
> (http://slashdot.org/features/980720/0819202.shtml)
>         "What is "security through obscurity""
> (http://users.softlab.ntua.gr/~taver/security/secur3.html)
> 
> For a wider discussion see
>         "Secrecy, Security, and Obscurity"
> (http://www.schneier.com/crypto-gram-0205.html)
> 
> 
> 
> 
> On 13 April 2010 21:22, Jim Seymour <[email protected]> wrote:
> >> From: "Behm, Jeff" <[email protected]>
> >> To: Firewall Wizards Security Mailing List
> >>       <[email protected]>
> >> Date: Tue, 13 Apr 2010 11:16:06 -0500
> >> Subject: [fw-wiz] DNS Names for external services
> >>
> >> Just curious, what is your opinions of the security vs. ease of use
> >> trade-offs on putting DNS entries in (vs. making people know/use an
> >> IP address) for services you expose to the Internet.
> > [snip]
> >
> > I believe there's nothing significant to be gained by such
> > obfuscation.
> >
> > Regards,
> > Jim
> > --
> > Note: My mail server employs *very* aggressive anti-spam
> > filtering.  If you reply to this email and your email is
> > rejected, please accept my apologies and let me know via my
> > web form at <http://jimsun.LinxNet.com/contact/scform.php>.
> > _______________________________________________
> > firewall-wizards mailing list
> > [email protected]
> > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> >
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.