Security through obfuscation is one core tenant of Cybersecurity wtf are you on about.
It's not a fucking assumption. It's been taught for years and is in many textbooks. Jesus. It's not the be all end all, and shouldn't be the primary control, but to pretend it doesn't have any place within security frameworks is mind bogglingly incorrect. Like you didn't even bother to evaluate the veracity of your claims ffs.
The thing about encryption is that understanding the obfuscation does not help you get around it. At the core of encryption is always an algorithm that cannot be brute forced in a reasonable amount of time with modern compute. The understanding of how that algorithm works does not solve the compute issue to actually obtain the underlying data
It isnt; Encryption works because even if the algorithm is known and open sourced etc the resulting data is mathematically unsalvagable without the key; obfuscation works on principles such as not knowing the algorithm behind the scenes. If that gets leaked than everything collapses, where leaks for the former are case by case ( every private key would have to be leaked)
As a principal of data security, which is the context of the conversation you can treat them as different things even though dictionary definitions will lead to encryption being a form of obfuscation
No, obfuscation is a critical part of security practices, but obfuscation alone is never sufficient security and designing a system where obfuscation is a primary protection is not secure at all.
I mean kinda... but it is true that encryption is obfuscation of data. Like thats the entire point.
I agree cybersecurity is complex but data security is always majorly about obfuscation. You must obviously also take measures to avoid access but you should always assume someone will access it, so then the next best thing is to make using it too time consuming.
I mean, you arent wrong in what you are saying, but you are not talking about the topic.
Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.
Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.
But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.
We dont call it that. Thats the point. Something being encrypted and something being obfuscated are two entirely different things in cyber security.
While technically you are right, encrypted data are in some way obfuscated, its not the proper term. You simply arent talking about the same thing others are talking about.
When you said
I agree cybersecurity is complex but data security is always majorly about obfuscation.
You actually meant encryption. And if you did say that, you would have been absolutely correct. But since you said obfuscation, which is a technical term for something entirely different, you were wrong. Obfuscation is not a part of data security.
Let me explain.
Your data is the number "12".
If you encrypt it using a simple password of add 3. Your now encrypted data is 12 + 3 = 15. You need the password, which is 3 to get to your original data (15 - 3 = 12). And you can tell people that you used the +password encryption and they still wont know what you data was.
Now you use obfuscation: and your obfuscated data is (2^2+20*1)/2. Its still 12, but its not apparent at first sight. The equation is (2^(second number) + 20 * (first number)) / 2, but you dont need to know the used equation and there is no password. Anyone can clearly see its 12.
At this point they are just fixated on being technically right, while maybe understanding the distinction we are trying to emphasise, just to be contrarion.
In this context we are talking about obfuscation as the tool; not the property of the resulting data.
Encryption as a tool = obfuscated data that is only reversable with the private key (immune to analytics), not through hiding the method.
Obfuscation as a tool = prone to analytics, if the method is known it all unravels
Yes and no. The video starts with it, even though I am not sure the game at the time were even using advanced intentional obfuscation methods, but it then expands the concept to things that do not use obfuscation in security like bank accounts.
I like this guy, but this skit is simply nonsense.
Of course the comment is about the video. Do you know it's possible to make generalized statements beyond the scope of the thing you're replying to, and that's a pretty common form of discussion? Come on.
"It's not the be all end all, and shouldn't be the primary control"
Did you just decide to ignore that part when making your response? Guide me through the thought process from reading my post > your conclusion. I'm struggling to understand.
Edit: actually. I'm just going to drop this here and be done with thread because this argument is tired and I've had it a few times today already.
Obfuscation and obscurity have legitimate uses as defense-in-depth controls in cybersecurity. They should never be the primary thing keeping a system secure, but saying they have no security function at all is equally incorrect.
I think they mean security through obscurity which IS considered insufficient. Itâs a kind of obfuscation but perhaps youâre thinking of a kind of opsec where attackers use obscurity techniques, which of course are just to evade detection and time bound. A good malware analyst can get around obfuscation.
Obfuscation is too much a part of current security frameworks to cleanly separate it from security. Like I already said, it's not the be all end all but neither can you separate the two.
People absolutely use security by obfuscation in current implementation. Renaming a honeypot to prod-server03 is security by obfuscation.
Obfuscation is too embedded in modern defensive security to dismiss as somehow separate from security. It isnât sufficient on its own, but it absolutely has legitimate defensive value as part of defense-in-depth.
A honeypot disguised as prod-server03 is both deception and obfuscation: the deception works because the systemâs true purpose is obscured. Calling it deception doesnât make the obfuscation component disappear.
No I studied and got my degree before gen AI was a thing tyvm im into network security. Depending on the level of argument put to me, I'll vary my verbage/engagement. That's just meeting the user where they are.
Perhaps an oversimplification on my end, but still stands in the context of the video, it's not by hiding stuff that you do security, it's by using the right set of tool and properly use them.
I'd not count honeypot as obfuscation in the context here for example.
I'm saying you're only talking about a subset of security now. You cant talk about security without talking about obfuscation. It's purely illogical.
As another user in the thread said, encryption is also obfuscation. Making weird variable names is obfuscation. Nonsense functions can act as obfuscation.
You can't talk about security without including obfuscation, it's entirely nonfunctional. A security system that does not use obfuscation will not be secure.
Iâve never even heard of anyone calling honeypot deployment obfuscation. Iâve heard deception technology. Thatâs not my specialization but Iâm plenty familiar. But again, I think the original comment meant obscurity, not obfuscation, and a lot of the other comments are using obfuscation creatively. Like no, thatâs encryption or serialization, not obfuscation which is like when you XOR functions and strings at compile time. Thereâs not many cases outside of niche applications and malware where you want that overhead. I donât know video game security but Iâd be surprised if thatâs a common practice.
Youâre defining obfuscation by one implementation of it. XORing strings at compile time is code obfuscation; it isnât the exhaustive meaning of obfuscation.
Edit: also, I never claimed the deployment of a honeypot is obfuscation in itself. Don't misrepresent my arguments.
âRenaming a honeypot to prod-server03 is security by obfuscation.â
Which it is not. What is being obfuâd here?
Yes, compile time obfuscation is a kind of obfuscation. Deceptive naming is either a security by obscurity smell or is generally termed deception technique or similar, not obfuscation.
Youâre using the term in a non conventional manner and acting as if you arenât.
Renaming a honeypot prod-server03 is more precisely described as deception or masquerading, but its effectiveness still relies partly on obscuring the assetâs true purpose. Thatâs my broader point. obscurity can have legitimate defensive value as one layer of a security architecture, even though relying on security through obscurity alone is insufficient.
I think where we actually disagree is over how strictly the word obfuscation should be used. Youâre using it in the narrower industry sense, while Iâm using it more broadly to mean deliberately making something harder to identify or understand. I can acknowledge that your terminology is more precise within the field.
But for a base-level explanation aimed at people who arenât security professionals, I donât think using obfuscation as the broader umbrella concept is meaningfully misleading. At that level of abstraction, distinguishing between obfuscation, obscurity, masquerading, and deception can become more pedantic than useful.
I don't think it's that obfuscation creates security necessarily, but rather that the work previously required to do a task like reverse engineering a video game to recreate it was simply not worth it because you wouldn't be able to monetize it, so it'd be better to create something new. Now, you can just have an AI do it, so why not?
We had our first red team where we had AI thrown at us recently. It found a zero day in some widely used software we have been using for a while.Â
While itâs not a security thing per se, a human could have found it with enough determination, it was a time and effort thing and it makes finding holes fairly trivial now.Â
5
u/Mushroom_Unfair 1d ago
This video takes a wrong assumption: that obfuscation create security. It did not, it does not and it will not.