SQL Server Central is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
Search:  
 
 

It Depends

Add to Technorati Favorites Add to Google
 

Security by Obscurity?

By Andy Warren in It Depends | 06-02-2008 1:32 AM | Categories: Filed under:
Rating: (not yet rated) |  Discuss | 536 Reads | 108 Reads in Last 30 Days |no comments

If you're not familiar with the term it means to make something safe/secure by using a trick to hide the vulnerability rather than fixing it, or perhaps when "fixing" it is just isn't possible. Over the years I've seen the value of running SQL on a non-standard port, threats drop to just about zero. On the other hand, I've never wanted to go to the extreme of renaming the administrator account or giving my service accounts names that look like "real" people.

This months TechNet Magazine has a great article The Great Debate: Security by Obscurity and I encourage you to read it, they present both points of view well and while no final all encompassing right answer, this will make sure you understand the value - or lack of - in the various ways we might use obscurity. Hoping I can get my friend Brian Kelley to post some notes, as he is the most security minded guy I know in the SQL space.

Comments
There are no comments on this post
Leave a Comment
Only members of SQLServerCentral may leave comments. Register now for your free account or Sign-In if you are already a member.