Was Rumpelstiltskin the First Documented Case of Security by Obscurity?
Cybersecurity has a long and distinguished history of people designing systems that are secure provided nobody discovers the thing they're not supposed to know. But perhaps the Brothers Grimm got there first.
Consider Rumpelstiltskin
A miller foolishly tells a king that his daughter can spin straw into gold. The king, displaying the sort of requirements-management skills that would later become commonplace in large IT programmes, locks her in a room full of straw and tells her to get on with it.
Unfortunately, she cannot actually spin straw into gold.
Fortunately - sort of - a mysterious little man appears and offers to do it for her.
First he takes her necklace. Then her ring. Finally, when she has nothing left to offer, he demands her first-born child.
She agrees.
Some time later, having married the king and produced the aforementioned child, our heroine discovers that Rumpelstiltskin takes contractual obligations rather seriously.
He arrives to collect.
After she begs him to reconsider, however, he offers an alternative.
If she can discover his name within three days, she can keep the baby.
And here we encounter what may be one of the earliest documented examples of a catastrophically flawed security architecture.
The Rumpelstiltskin Security Model
Let's perform a quick threat assessment.
| Asset | First-born child |
|---|---|
| Secret | Rumpelstiltskin's name |
| Authentication mechanism | Knowledge of secret |
| Threat actor | Queen |
| Security assumption | Nobody knows the secret |
| Attack | Reconnaissance / HUMINT |
| Vulnerability | Information disclosure |
| Impact | Total compromise |
The Queen begins trying names.
Lots of names.
But brute force isn't getting her anywhere.
So she changes strategy.
She sends people out into the countryside looking for information.
And eventually one of her messengers discovers a small man dancing around a fire in the forest.
Rumpelstiltskin is celebrating his impending victory.
Unfortunately, while doing so, he sings a song containing his own supposedly secret name.
This is not good OPSEC.
The messenger reports back.
The following day the Queen presents Rumpelstiltskin with the discovered credential.
Access granted.
Game over.
Rumpelstiltskin responds to this security incident by stamping his foot through the floor and ultimately tearing himself in half.
This incident-response procedure is not currently recommended by NIST.
So Is This Really Security by Obscurity?
Well...
Not quite.
There's an important distinction here.
Keeping a credential secret is perfectly sensible. Passwords, private keys and cryptographic secrets really are supposed to remain secret.
What security engineers usually mean by security by obscurity is designing a system whose security depends upon an attacker not understanding how the system itself works.
Modern security engineering takes almost the opposite approach.
The attacker should be allowed to understand the architecture, protocols and algorithms and the system should still remain secure.
This idea was famously formalised in the nineteenth century by cryptographer Auguste Kerckhoffs: a cryptographic system should remain secure even if everything about it, except the key, is public knowledge.
Modern cryptography follows exactly this philosophy.
We don't keep AES secret.
We publish precisely how it works.
Everyone - including attackers - is welcome to study it.
The security lies in protecting the key, not hiding the algorithm.
Rumpelstiltskin's Real Security Failure
So Rumpelstiltskin's problem wasn't merely security by obscurity.
It was arguably worse.
He created an authentication system based upon possession of a secret...
...and then wandered into the woods and sang the credential out loud.
The Queen didn't break his authentication mechanism.
She didn't brute-force it.
She didn't exploit some clever cryptographic weakness.
She simply performed reconnaissance until somebody leaked the credential.
Which, more than 200 years after the Brothers Grimm published the story, remains an alarmingly effective way of compromising computer systems.
So perhaps Rumpelstiltskin isn't really the world's first documented example of security by obscurity.
But it may be one of the earliest lessons in credential management, information disclosure and terrible operational security.
The Moral of the Story?
Design your security on the assumption that your adversary understands how your system works.
Protect your keys.
Protect your credentials.
And if your entire security model depends upon nobody discovering your name...
Don't dance around a fire singing it at the top of your $%^*()g voice!