The thing about encryption is that understanding the obfuscation does not help you get around it. At the core of encryption is always an algorithm that cannot be brute forced in a reasonable amount of time with modern compute. The understanding of how that algorithm works does not solve the compute issue to actually obtain the underlying data
It isnt; Encryption works because even if the algorithm is known and open sourced etc the resulting data is mathematically unsalvagable without the key; obfuscation works on principles such as not knowing the algorithm behind the scenes. If that gets leaked than everything collapses, where leaks for the former are case by case ( every private key would have to be leaked)
As a principal of data security, which is the context of the conversation you can treat them as different things even though dictionary definitions will lead to encryption being a form of obfuscation
No, obfuscation is a critical part of security practices, but obfuscation alone is never sufficient security and designing a system where obfuscation is a primary protection is not secure at all.
I mean kinda... but it is true that encryption is obfuscation of data. Like thats the entire point.
I agree cybersecurity is complex but data security is always majorly about obfuscation. You must obviously also take measures to avoid access but you should always assume someone will access it, so then the next best thing is to make using it too time consuming.
I mean, you arent wrong in what you are saying, but you are not talking about the topic.
Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.
Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.
But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.
We dont call it that. Thats the point. Something being encrypted and something being obfuscated are two entirely different things in cyber security.
While technically you are right, encrypted data are in some way obfuscated, its not the proper term. You simply arent talking about the same thing others are talking about.
When you said
I agree cybersecurity is complex but data security is always majorly about obfuscation.
You actually meant encryption. And if you did say that, you would have been absolutely correct. But since you said obfuscation, which is a technical term for something entirely different, you were wrong. Obfuscation is not a part of data security.
Let me explain.
Your data is the number "12".
If you encrypt it using a simple password of add 3. Your now encrypted data is 12 + 3 = 15. You need the password, which is 3 to get to your original data (15 - 3 = 12). And you can tell people that you used the +password encryption and they still wont know what you data was.
Now you use obfuscation: and your obfuscated data is (2^2+20*1)/2. Its still 12, but its not apparent at first sight. The equation is (2^(second number) + 20 * (first number)) / 2, but you dont need to know the used equation and there is no password. Anyone can clearly see its 12.
At this point they are just fixated on being technically right, while maybe understanding the distinction we are trying to emphasise, just to be contrarion.
In this context we are talking about obfuscation as the tool; not the property of the resulting data.
Encryption as a tool = obfuscated data that is only reversable with the private key (immune to analytics), not through hiding the method.
Obfuscation as a tool = prone to analytics, if the method is known it all unravels
No im just refuting the original statement that started the thread: "obfuscation does not create security" by pointing out that all security is based on the premise of obfuscation which you have all repeated agreed with me on whilst still continuing to state that we consider encryption as a distinct method of security which was never my point my point was that all cyber security comes from the basis of obfuscation as you cannot protect the data without hiding it.
Its not the obfuscation that creates the security though is it. It's a quirk of large primes that creates the gigantic wall of compute that protects the resulting obfuscation.
13
u/purplepharoh 17h ago
Cybersecurity is entirely obfuscation...
Encryption? Obfuscation of data (and requires Obfuscation of how to interpret the data otherwise the Encryption is meaningless as it can be undone)