Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> “My trust policy has a vulnerability in it but I’m safe because the attacker can’t read my policy to find out”

The goal in preventing enumeration isn't to hide defects in the security policy. The goal is to make it more difficult for attackers to determine what and how they need to attack to move closer to their target. Less information about what privileges a given user/role have = more noise from the attacker, and more dwell time, all other things being equal. Both of which increase the likelihood of detection prior to full compromise.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: