Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Throughout this chapter we have described design weaknesses, for example, exchanges in which the user can see and perhaps predict, guess, or intercept a supposedly secret magic number or string. Obscurity, assuming the user will be too naïve to guess or predict a token or too inept to intercept it, is not a solid security foundation. These examples underscore a point made several times in this book: Security through obscurity is not secure.