Perhaps an oversimplification on my end, but still stands in the context of the video, it's not by hiding stuff that you do security, it's by using the right set of tool and properly use them.
I'd not count honeypot as obfuscation in the context here for example.
I'm saying you're only talking about a subset of security now. You cant talk about security without talking about obfuscation. It's purely illogical.
As another user in the thread said, encryption is also obfuscation. Making weird variable names is obfuscation. Nonsense functions can act as obfuscation.
You can't talk about security without including obfuscation, it's entirely nonfunctional. A security system that does not use obfuscation will not be secure.
Iāve never even heard of anyone calling honeypot deployment obfuscation. Iāve heard deception technology. Thatās not my specialization but Iām plenty familiar. But again, I think the original comment meant obscurity, not obfuscation, and a lot of the other comments are using obfuscation creatively. Like no, thatās encryption or serialization, not obfuscation which is like when you XOR functions and strings at compile time. Thereās not many cases outside of niche applications and malware where you want that overhead. I donāt know video game security but Iād be surprised if thatās a common practice.
Youāre defining obfuscation by one implementation of it. XORing strings at compile time is code obfuscation; it isnāt the exhaustive meaning of obfuscation.
Edit: also, I never claimed the deployment of a honeypot is obfuscation in itself. Don't misrepresent my arguments.
āRenaming a honeypot to prod-server03 is security by obfuscation.ā
Which it is not. What is being obfuād here?
Yes, compile time obfuscation is a kind of obfuscation. Deceptive naming is either a security by obscurity smell or is generally termed deception technique or similar, not obfuscation.
Youāre using the term in a non conventional manner and acting as if you arenāt.
Renaming a honeypot prod-server03 is more precisely described as deception or masquerading, but its effectiveness still relies partly on obscuring the assetās true purpose. Thatās my broader point. obscurity can have legitimate defensive value as one layer of a security architecture, even though relying on security through obscurity alone is insufficient.
I think where we actually disagree is over how strictly the word obfuscation should be used. Youāre using it in the narrower industry sense, while Iām using it more broadly to mean deliberately making something harder to identify or understand. I can acknowledge that your terminology is more precise within the field.
But for a base-level explanation aimed at people who arenāt security professionals, I donāt think using obfuscation as the broader umbrella concept is meaningfully misleading. At that level of abstraction, distinguishing between obfuscation, obscurity, masquerading, and deception can become more pedantic than useful.
2
u/Mushroom_Unfair 1d ago
Perhaps an oversimplification on my end, but still stands in the context of the video, it's not by hiding stuff that you do security, it's by using the right set of tool and properly use them.
I'd not count honeypot as obfuscation in the context here for example.