> security is not gained through obscurity
However, this one is tricky; it's been circulating as an unfinished rational-religious dogma in software development communities.
The complete correct statement is security *only* through obscurity is bad, e.g. security only through steganography is bad (while a combination of both may produce a synergic effect—improve plausible deniability).
Yet obscurity still introduces complexity, so it should be wisely balanced when necessary to have at all.
#devstr
https://mobeigi.com/blog/security/security-through-obscurity-is-not-bad/