Searching for Insecurity
Posted Sep 29, 2006 18:32 UTC (Fri) by
giraffedata (subscriber, #1954)
In reply to:
Searching for Insecurity by dion
Parent article:
Searching for Insecurity
There is absolutely no reason at all to tell the attackers the exact version of software you are running
There's a good reason to tell the attackers the version of the software: You can't know that the person you're telling is an attacker, and non-attackers have lots of good uses for that information. It's especially useful in diagnosing problems. It's also handy in release management.
I believe obscurity usually improves security. But that improvement does come at a cost.
(
Log in to post comments)