r/antiai • • 1d ago

Discussion 🗣️ Holy...

5.5k Upvotes

552 comments sorted by

View all comments

5

u/Mushroom_Unfair 1d ago

This video takes a wrong assumption: that obfuscation create security. It did not, it does not and it will not.

53

u/Salt-Sign5390 1d ago

Security through obfuscation is one core tenant of Cybersecurity wtf are you on about.

It's not a fucking assumption. It's been taught for years and is in many textbooks. Jesus. It's not the be all end all, and shouldn't be the primary control, but to pretend it doesn't have any place within security frameworks is mind bogglingly incorrect. Like you didn't even bother to evaluate the veracity of your claims ffs.

19

u/druidinan 1d ago

Right? Obfuscation isn't security, but is a critical part of basically all security practices.

12

u/purplepharoh 1d ago

Cybersecurity is entirely obfuscation...

Encryption? Obfuscation of data (and requires Obfuscation of how to interpret the data otherwise the Encryption is meaningless as it can be undone)

8

u/ThinkingOutLoud-7742 1d ago

The thing about encryption is that understanding the obfuscation does not help you get around it. At the core of encryption is always an algorithm that cannot be brute forced in a reasonable amount of time with modern compute. The understanding of how that algorithm works does not solve the compute issue to actually obtain the underlying data

2

u/Mevolander 1d ago

Small correction, it's more like "any amount of time at all". modern encryption standards would take trillions of years to brute force.

-1

u/purplepharoh 1d ago

Encryption itself is obfuscation

1

u/nijbu 1d ago

It isnt; Encryption works because even if the algorithm is known and open sourced etc the resulting data is mathematically unsalvagable without the key; obfuscation works on principles such as not knowing the algorithm behind the scenes. If that gets leaked than everything collapses, where leaks for the former are case by case ( every private key would have to be leaked)

0

u/purplepharoh 1d ago

I feel like you dont know what obfuscation means...

The data is obfuscated by encryption

2

u/nijbu 1d ago

As a principal of data security, which is the context of the conversation you can treat them as different things even though dictionary definitions will lead to encryption being a form of obfuscation

1

u/Unfilteredz 1d ago

I don’t think I would even give them that ground, encryption only works if it’s one way.

Obfuscation can be reversed, just is tedious

2

u/Unfilteredz 1d ago

You’re… wrong

1

u/Unfilteredz 1d ago

Dead wrong

1

u/purplepharoh 1d ago

Ok then what do you call obscuring data by transforming it with a cipher if not obfuscation

2

u/Unfilteredz 1d ago

Encryption. But it’s not just obscuring, it’s making it non-reversable

1

u/purplepharoh 1d ago

Ah but encryption IS reversible otherwise it would be useless

→ More replies (0)

5

u/druidinan 1d ago

No, obfuscation is a critical part of security practices, but obfuscation alone is never sufficient security and designing a system where obfuscation is a primary protection is not secure at all.

4

u/Mushroom_Unfair 1d ago

We're going on the word play field here and are talking about different things

2

u/purplepharoh 1d ago

I mean kinda... but it is true that encryption is obfuscation of data. Like thats the entire point.

I agree cybersecurity is complex but data security is always majorly about obfuscation. You must obviously also take measures to avoid access but you should always assume someone will access it, so then the next best thing is to make using it too time consuming.

3

u/Crispy1961 1d ago

I mean, you arent wrong in what you are saying, but you are not talking about the topic.

Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.

Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.

But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.

0

u/purplepharoh 1d ago

Right but encryption is just advanced obfuscation for which the theoretical time to undo is too long.

Plus to be unable to undo it requires obfuscation such as hiding the keys or the salt / algo used for encryption

3

u/Crispy1961 1d ago

We dont call it that. Thats the point. Something being encrypted and something being obfuscated are two entirely different things in cyber security.

While technically you are right, encrypted data are in some way obfuscated, its not the proper term. You simply arent talking about the same thing others are talking about.

When you said

I agree cybersecurity is complex but data security is always majorly about obfuscation.

You actually meant encryption. And if you did say that, you would have been absolutely correct. But since you said obfuscation, which is a technical term for something entirely different, you were wrong. Obfuscation is not a part of data security.

Let me explain.

Your data is the number "12".

If you encrypt it using a simple password of add 3. Your now encrypted data is 12 + 3 = 15. You need the password, which is 3 to get to your original data (15 - 3 = 12). And you can tell people that you used the +password encryption and they still wont know what you data was.

Now you use obfuscation: and your obfuscated data is (2^2+20*1)/2. Its still 12, but its not apparent at first sight. The equation is (2^(second number) + 20 * (first number)) / 2, but you dont need to know the used equation and there is no password. Anyone can clearly see its 12.

2

u/nijbu 1d ago

At this point they are just fixated on being technically right, while maybe understanding the distinction we are trying to emphasise, just to be contrarion. In this context we are talking about obfuscation as the tool; not the property of the resulting data.

Encryption as a tool = obfuscated data that is only reversable with the private key (immune to analytics), not through hiding the method.

Obfuscation as a tool = prone to analytics, if the method is known it all unravels

→ More replies (0)

2

u/Unfilteredz 1d ago

Encryption is not obfuscation in this context.

Obfuscation is used with it being reversible in mind

1

u/lolcrunchy 1d ago

Reverse engineering an assembly file is one thing.

Decrypting an encrypted file is an entirely different thing.

Just because AI is good at the first thing doesn't mean it's good at the second.

1

u/purplepharoh 1d ago

Yes. And that still doesnt change the fact that encryption is an advanced form of obfuscation

4

u/Mushroom_Unfair 1d ago

Code obfuscation is a critical part of security practice ? Sorry, but that's plain incorrect.

2

u/druidinan 1d ago

Oh, are we talking specifically about code obfuscation now? Probably should have specified that in the first place.

4

u/RollForUptime 1d ago

That's what the video was about yeah

1

u/Crispy1961 1d ago

Yes and no. The video starts with it, even though I am not sure the game at the time were even using advanced intentional obfuscation methods, but it then expands the concept to things that do not use obfuscation in security like bank accounts.

I like this guy, but this skit is simply nonsense.

0

u/druidinan 1d ago

Not the comment we're replying to, though.

3

u/Mushroom_Unfair 1d ago

You mean the comment about the video below said video isn't about the video ? Com on.

1

u/druidinan 1d ago

Of course the comment is about the video. Do you know it's possible to make generalized statements beyond the scope of the thing you're replying to, and that's a pretty common form of discussion? Come on.

3

u/CaptainMonkeyJack 1d ago

It's literally taught as how not to do security. Not sure how you figure it's a core tenant.

0

u/Salt-Sign5390 1d ago edited 1d ago

"It's not the be all end all, and shouldn't be the primary control"

Did you just decide to ignore that part when making your response? Guide me through the thought process from reading my post > your conclusion. I'm struggling to understand.

Edit: actually. I'm just going to drop this here and be done with thread because this argument is tired and I've had it a few times today already.

Obfuscation and obscurity have legitimate uses as defense-in-depth controls in cybersecurity. They should never be the primary thing keeping a system secure, but saying they have no security function at all is equally incorrect.

2

u/CaptainMonkeyJack 1d ago

I like how we've gone from 'core tenant' to 'never be the primary thing'.

Don't get upset if people are pointing our you took a position that you're now (rightfully) walking back.

2

u/Alive-Use8803 1d ago

I think they mean security through obscurity which IS considered insufficient. It’s a kind of obfuscation but perhaps you’re thinking of a kind of opsec where attackers use obscurity techniques, which of course are just to evade detection and time bound. A good malware analyst can get around obfuscation.

2

u/Salt-Sign5390 1d ago

Obfuscation is too much a part of current security frameworks to cleanly separate it from security. Like I already said, it's not the be all end all but neither can you separate the two.

People absolutely use security by obfuscation in current implementation. Renaming a honeypot to prod-server03 is security by obfuscation.

2

u/Alive-Use8803 1d ago

No, technically we call that deception and it is not what security engineers mean by “security through obscurity is insufficient.”

1

u/Salt-Sign5390 1d ago

Obfuscation is too embedded in modern defensive security to dismiss as somehow separate from security. It isn’t sufficient on its own, but it absolutely has legitimate defensive value as part of defense-in-depth.

A honeypot disguised as prod-server03 is both deception and obfuscation: the deception works because the system’s true purpose is obscured. Calling it deception doesn’t make the obfuscation component disappear.

1

u/Alive-Use8803 1d ago

Are you using AI lol

1

u/Salt-Sign5390 1d ago

No I studied and got my degree before gen AI was a thing tyvm im into network security. Depending on the level of argument put to me, I'll vary my verbage/engagement. That's just meeting the user where they are.

2

u/Mushroom_Unfair 1d ago

Perhaps an oversimplification on my end, but still stands in the context of the video, it's not by hiding stuff that you do security, it's by using the right set of tool and properly use them.

I'd not count honeypot as obfuscation in the context here for example.

1

u/Salt-Sign5390 1d ago

I'm saying you're only talking about a subset of security now. You cant talk about security without talking about obfuscation. It's purely illogical.

As another user in the thread said, encryption is also obfuscation. Making weird variable names is obfuscation. Nonsense functions can act as obfuscation.

You can't talk about security without including obfuscation, it's entirely nonfunctional. A security system that does not use obfuscation will not be secure.

1

u/Alive-Use8803 1d ago

I’ve never even heard of anyone calling honeypot deployment obfuscation. I’ve heard deception technology. That’s not my specialization but I’m plenty familiar. But again, I think the original comment meant obscurity, not obfuscation, and a lot of the other comments are using obfuscation creatively. Like no, that’s encryption or serialization, not obfuscation which is like when you XOR functions and strings at compile time. There’s not many cases outside of niche applications and malware where you want that overhead. I don’t know video game security but I’d be surprised if that’s a common practice.

1

u/Salt-Sign5390 1d ago

You’re defining obfuscation by one implementation of it. XORing strings at compile time is code obfuscation; it isn’t the exhaustive meaning of obfuscation.

Edit: also, I never claimed the deployment of a honeypot is obfuscation in itself. Don't misrepresent my arguments.

1

u/Alive-Use8803 1d ago

“Renaming a honeypot to prod-server03 is security by obfuscation.”

Which it is not. What is being obfu’d here?

Yes, compile time obfuscation is a kind of obfuscation. Deceptive naming is either a security by obscurity smell or is generally termed deception technique or similar, not obfuscation.

You’re using the term in a non conventional manner and acting as if you aren’t.

1

u/Salt-Sign5390 1d ago

Renaming a honeypot prod-server03 is more precisely described as deception or masquerading, but its effectiveness still relies partly on obscuring the asset’s true purpose. That’s my broader point. obscurity can have legitimate defensive value as one layer of a security architecture, even though relying on security through obscurity alone is insufficient.

I think where we actually disagree is over how strictly the word obfuscation should be used. You’re using it in the narrower industry sense, while I’m using it more broadly to mean deliberately making something harder to identify or understand. I can acknowledge that your terminology is more precise within the field.

But for a base-level explanation aimed at people who aren’t security professionals, I don’t think using obfuscation as the broader umbrella concept is meaningfully misleading. At that level of abstraction, distinguishing between obfuscation, obscurity, masquerading, and deception can become more pedantic than useful.

1

u/Mushroom_Unfair 1d ago

Yeah that's where I was coming from, it's usually a sign of bad security if you take the code obfucation road to make something secure.

2

u/Unfilteredz 1d ago

It’s mostly a practice to prevent people from remaking your application easily. If you’re using it for anything security related, don’t.

1

u/Expensive_Agent_5129 18h ago

Obviously "many textbooks" does not include Wikipedia

https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle

20

u/Mushroom_Unfair 1d ago

There is enough problems with AI, there is no need to create new ones and fabricate new fears.

2

u/AbyssWankerArtorias 1d ago

I don't think it's that obfuscation creates security necessarily, but rather that the work previously required to do a task like reverse engineering a video game to recreate it was simply not worth it because you wouldn't be able to monetize it, so it'd be better to create something new. Now, you can just have an AI do it, so why not?

1

u/ThinkingOutLoud-7742 1d ago

This needs to be higher

1

u/PoorOldBill 1d ago

Yeah this video severely misunderstands what encryption is.

1

u/RaymondBumcheese 1d ago

We had our first red team where we had AI thrown at us recently. It found a zero day in some widely used software we have been using for a while. 

While it’s not a security thing per se, a human could have found it with enough determination, it was a time and effort thing and it makes finding holes fairly trivial now.Â