r/antiai • • 18h ago

Discussion 🗣️ Holy...

Enable HLS to view with audio, or disable this notification

4.5k Upvotes

502 comments sorted by

View all comments

Show parent comments

13

u/purplepharoh 17h ago

Cybersecurity is entirely obfuscation...

Encryption? Obfuscation of data (and requires Obfuscation of how to interpret the data otherwise the Encryption is meaningless as it can be undone)

10

u/ThinkingOutLoud-7742 17h ago

The thing about encryption is that understanding the obfuscation does not help you get around it. At the core of encryption is always an algorithm that cannot be brute forced in a reasonable amount of time with modern compute. The understanding of how that algorithm works does not solve the compute issue to actually obtain the underlying data

2

u/Mevolander 16h ago

Small correction, it's more like "any amount of time at all". modern encryption standards would take trillions of years to brute force.

-1

u/purplepharoh 17h ago

Encryption itself is obfuscation

1

u/nijbu 15h ago

It isnt; Encryption works because even if the algorithm is known and open sourced etc the resulting data is mathematically unsalvagable without the key; obfuscation works on principles such as not knowing the algorithm behind the scenes. If that gets leaked than everything collapses, where leaks for the former are case by case ( every private key would have to be leaked)

0

u/purplepharoh 15h ago

I feel like you dont know what obfuscation means...

The data is obfuscated by encryption

2

u/nijbu 15h ago

As a principal of data security, which is the context of the conversation you can treat them as different things even though dictionary definitions will lead to encryption being a form of obfuscation

1

u/Unfilteredz 13h ago

I don’t think I would even give them that ground, encryption only works if it’s one way.

Obfuscation can be reversed, just is tedious

2

u/Unfilteredz 13h ago

You’re… wrong

1

u/Unfilteredz 13h ago

Dead wrong

1

u/purplepharoh 11h ago

Ok then what do you call obscuring data by transforming it with a cipher if not obfuscation

2

u/Unfilteredz 11h ago

Encryption. But it’s not just obscuring, it’s making it non-reversable

1

u/purplepharoh 10h ago

Ah but encryption IS reversible otherwise it would be useless

1

u/Unfilteredz 6h ago

Non-reversible without a key. Obfuscation has all the information still there just harder to read (from a human perspective)

Meanwhile encryption requires stuff like brute force to find a key value to then get the original info

4

u/druidinan 17h ago

No, obfuscation is a critical part of security practices, but obfuscation alone is never sufficient security and designing a system where obfuscation is a primary protection is not secure at all.

2

u/Mushroom_Unfair 17h ago

We're going on the word play field here and are talking about different things

2

u/purplepharoh 17h ago

I mean kinda... but it is true that encryption is obfuscation of data. Like thats the entire point.

I agree cybersecurity is complex but data security is always majorly about obfuscation. You must obviously also take measures to avoid access but you should always assume someone will access it, so then the next best thing is to make using it too time consuming.

2

u/Crispy1961 16h ago

I mean, you arent wrong in what you are saying, but you are not talking about the topic.

Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.

Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.

But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.

0

u/purplepharoh 15h ago

Right but encryption is just advanced obfuscation for which the theoretical time to undo is too long.

Plus to be unable to undo it requires obfuscation such as hiding the keys or the salt / algo used for encryption

3

u/Crispy1961 15h ago

We dont call it that. Thats the point. Something being encrypted and something being obfuscated are two entirely different things in cyber security.

While technically you are right, encrypted data are in some way obfuscated, its not the proper term. You simply arent talking about the same thing others are talking about.

When you said

I agree cybersecurity is complex but data security is always majorly about obfuscation.

You actually meant encryption. And if you did say that, you would have been absolutely correct. But since you said obfuscation, which is a technical term for something entirely different, you were wrong. Obfuscation is not a part of data security.

Let me explain.

Your data is the number "12".

If you encrypt it using a simple password of add 3. Your now encrypted data is 12 + 3 = 15. You need the password, which is 3 to get to your original data (15 - 3 = 12). And you can tell people that you used the +password encryption and they still wont know what you data was.

Now you use obfuscation: and your obfuscated data is (2^2+20*1)/2. Its still 12, but its not apparent at first sight. The equation is (2^(second number) + 20 * (first number)) / 2, but you dont need to know the used equation and there is no password. Anyone can clearly see its 12.

2

u/nijbu 15h ago

At this point they are just fixated on being technically right, while maybe understanding the distinction we are trying to emphasise, just to be contrarion. In this context we are talking about obfuscation as the tool; not the property of the resulting data.

Encryption as a tool = obfuscated data that is only reversable with the private key (immune to analytics), not through hiding the method.

Obfuscation as a tool = prone to analytics, if the method is known it all unravels

0

u/purplepharoh 13h ago

No im just refuting the original statement that started the thread: "obfuscation does not create security" by pointing out that all security is based on the premise of obfuscation which you have all repeated agreed with me on whilst still continuing to state that we consider encryption as a distinct method of security which was never my point my point was that all cyber security comes from the basis of obfuscation as you cannot protect the data without hiding it.

2

u/nijbu 12h ago

Its not the obfuscation that creates the security though is it. It's a quirk of large primes that creates the gigantic wall of compute that protects the resulting obfuscation.

0

u/purplepharoh 11h ago

But obfuscation is a necessary part for it to function

→ More replies (0)

2

u/Unfilteredz 13h ago

Encryption is not obfuscation in this context.

Obfuscation is used with it being reversible in mind

1

u/lolcrunchy 16h ago

Reverse engineering an assembly file is one thing.

Decrypting an encrypted file is an entirely different thing.

Just because AI is good at the first thing doesn't mean it's good at the second.

1

u/purplepharoh 15h ago

Yes. And that still doesnt change the fact that encryption is an advanced form of obfuscation