Skip to content

Comment on GitHub Thinks I'm a Robot

Comments

Sorry, but we have to keep our spam-detecting tactics hush-hush. If I were to share that information and word got out, it would be like releasing access to some of our security protocols into the big, wide world. I hope you understand.

I don't know much about spam-fighting, so I don't know to what extent this "obscurity" strategy is viable there, but this is at best a bad analogy since the consensus seems to be that security protocols that you have to hide are not good security protocols.

Keeping a capability secret is a perfectly valid approach to providing security. If you publicise a capability then an attacker can work to defeat that capability very easily and directly. By keeping it secret you force the attacker to first find out you have it and unpick that capability in order to defeat it.

Security by obscurity cannot be the only approach to security, but it's certainly a valid tool. Militaries and security services the world over rely on it throughout history for instance.

I can only guess that "obscurity" is an excuse for the defects of GitHub's machine learning of spammer detection. The spammers can always check if their accounts have profiles even if there is no notification.

(Don't know why you and all my neutral comments are downvoted. Angry GitHub employees here?)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.