| |
| | Insecurity through obscurity |
 | | However, Auguste Kerckhoffs, a 19th century Flemish cryptographer, said it should be assumed that attackers know the design of the entire security system, except for the keys. |
 | | This concept, known as Kerckhoffs' law, basically rejected the notion of security through obscurity (your key hidden under your potted plant) and suggested that a system should be secure even if everything's public knowledge, except the key. |
 | | Companies and software developers need to start with Kerckhoffs' law, assume that the algorithm and design of the software are known, and design security into the products and software in the beginning instead of retrofitting or patching security holes later. |
| www.computerworld.com /printthis/2005/0,4814,102307,00.html (794 words) |
|