upvote
This is oversimplifying.

For example, encryption at rest or in transit essentially eliminates attack vectors. The possible attack avenues necessarily shift as a result, but only because an avenue was blocked.

That's very different from e.g. adding a layer of protection around something insecure, where the insecure thing remains insecure inside the protection, which I think is what the other commenter was imagining.

Similarly, memory safe languages (including most GC languages, not just a certain language beginning with R) eliminate entire classes of security hole. Again, the possible attack vectors necessarily "shift", but that doesn't capture the fact that you've entirely eliminated a class of attacks.

The same goes for eliminating unnecessary services, firewall holes, etc.

None of these are specifically trying to "shift it to something to something that is more difficult to compromise." They're entirely blocking attack vectors, and the strength or weakness of other parts of the system aren't really a factor.

reply
Doesn’t encryption shift the attack vector to the key and/or the method?
reply
That's a different attack vector. The attack vector that involves accessing plain text has been eliminated. An attack vector is a specific path or method that can be used to break into a system.
reply
What? Encryption has never eliminated attack vectors, it just shifts them to weaknesses in the implementation
reply
Eliminating an attack vector means stopping a specific path or method that can be used to break into a system.

"Shift" in this context means that the attacker has to use a different attack vector. They can no longer just access plain text.

reply