Security question: Is it a good practice to name folders on the server by names that are difficult to guess (8+ symbols, not a simple “admin” or “services”)? I’m asking about folders that contain not just icons or .js files or .css files, but .php files and are protected by .htaccess file (deny from all).
Share
No. Security through obscurity isn’t.
Plus it’s really irritating for anybody using the machine via a shell, ftp, etc.
What would it protect against? Regardless of names, folder access should be handled by the machine’s and/or network’s normal security mechanisms. If they get past that, it doesn’t matter what your artifacts are named–Ur PwNeD.