A good security architecture should always be created under the assumption
that attackers will know everything about the architecture except secret
authentication information
If you're one of those organizations that require security vendors to agree
to complete secrecy about the fact that you've purchased and deployed their
products, you should probably reconsider your policies in this area. In addition
to ignoring best practices that have withstood 125 years of scrutiny, you are
not really getting any additional security by doing this. And by restricting the
flow of information about the quality of security products, you are contributing
to a situation that makes things worse for both the producers and consumers of
security technologies. Security through obscurity has never been a good idea,
and it still isn't a good idea today.
In an 1883 article in Journal des Sciences Militaires, Auguste Kerchoffs
defined six principles that a secure communication system should follow. Despite
the considerable changes in technology, these principles are still as valid
today as they were in the 19th century.
The second of these principles is widely known today as 'Kerckhoffs'
Principle', and is often stated as the rule that the strength of a cryptographic
system should rely only on the secrecy of a cryptographic key. Kerckhoffs'
original statement, however, was actually more general than this, and deserves
revisiting by many users of security technologies.
Kerckhoffs stated his second principle as 'Il faut qu'il n'exige pas le
secret, et qu'il puisse sans inconvénient tomber entre les mains de l'ennemi',
which can be translated roughly as 'It must not require secrecy, and can be used
even if it falls into enemy hands'.
/dqc/media/post_attachments/401952de8412a567e9a4329a667ee8cffbcba775db6ee4f35b72c503c5ba3ead.jpg)
So even if hackers know everything about your system, if they don't have the
cryptographic keys you use to encrypt, any data they manage to get will be
useless to them because they won't be able to unscramble the encrypted
information.
In a more general sense, a hacker should be able know everything about your
security systems and still be unable to defeat them unless he knows the secrets
that you use to identify authorized users. Those secrets could be encryption
keys, but they could just as easily be other secret information, like a
password.
So a good security architecÂture should always be created under the
assumption that attackers will know everything about the architecture except
secret authentication information. This certainly includes assuming that
attackers know what they're attacking. So 'security through obscurity' is bad,
and has been known to be bad for 125 years.
This principle seems to have been forgotten by many corporate IT departments,
who all too often require security vendors to agree to extremely draconian terms
of secrecy as part of the terms and conditions of buying security products. This
unnecessary secrecy clearly violates the tried-and-true principles that
Kerckhoffs laid down in 1883, but it also causes considerable inefficiency in
the information security market, which benefits neither security vendors nor
their customers.
| Check points for a robust security architecture |
|
Many security products are what economists call 'experience goods', those for
which you can't easily tell their quality before you buy them, but for which the
quality becomes obvious after they're consumed or used. You may not know in
advance if an intrusion-detection system will be effective before you deploy it,
for example, but you can easily look at the logs of a deployed system and see
that it's working.
Some are even 'credence goods', those for which you generally can never tell
their quality, even after they're used. Encryption may be an example of this,
because it's essentially impossible for all but experts to tell strong
encryption from very weak encryption due to the rare and specialized skills
needed to analyze it.
Knowing the quality of goods before they're purchased is important to the
efficient operation of a market, and uncertainty in this area can lead to bad
things happening, and understanding the consequences of such uncertainty can be
very important. It's so important, that economist George Akerloff was awarded
the Nobel Prize in Economics in 2001 for his analysis of how such uncertainty
can adversely affect markets, even driving high-quality products from the market
and leaving only low-quality products at high prices as the only alternative for
consumers if market forces are left unchecked.
Users of security products benefit because they will more easily be able to
avoid low-quality products and avoid pitfalls with the products that they have
already deployed. It's tougher on the vendors of security products, because
exposing the weaknesses in their products will cause additional work, and they
will be more motivated to create more robust products and to fix existing
problems in their shipping products.
On the other hand, the gains from more information about the quality of
products should also benefit the vendors, at least those who make robust
products. A significant part of the cost of enterprise security products is due
to the long and expensive sales cycle that they require, and this cycle could
almost certainly be reduced in both length and cost if more information was
available to potential customers.
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us