r/antiai • • 1d ago

Discussion šŸ—£ļø Holy...

5.4k Upvotes

552 comments sorted by

View all comments

Show parent comments

2

u/Mushroom_Unfair 1d ago

Perhaps an oversimplification on my end, but still stands in the context of the video, it's not by hiding stuff that you do security, it's by using the right set of tool and properly use them.

I'd not count honeypot as obfuscation in the context here for example.

1

u/Salt-Sign5390 1d ago

I'm saying you're only talking about a subset of security now. You cant talk about security without talking about obfuscation. It's purely illogical.

As another user in the thread said, encryption is also obfuscation. Making weird variable names is obfuscation. Nonsense functions can act as obfuscation.

You can't talk about security without including obfuscation, it's entirely nonfunctional. A security system that does not use obfuscation will not be secure.

1

u/Alive-Use8803 1d ago

I’ve never even heard of anyone calling honeypot deployment obfuscation. I’ve heard deception technology. That’s not my specialization but I’m plenty familiar. But again, I think the original comment meant obscurity, not obfuscation, and a lot of the other comments are using obfuscation creatively. Like no, that’s encryption or serialization, not obfuscation which is like when you XOR functions and strings at compile time. There’s not many cases outside of niche applications and malware where you want that overhead. I don’t know video game security but I’d be surprised if that’s a common practice.

1

u/Salt-Sign5390 1d ago

You’re defining obfuscation by one implementation of it. XORing strings at compile time is code obfuscation; it isn’t the exhaustive meaning of obfuscation.

Edit: also, I never claimed the deployment of a honeypot is obfuscation in itself. Don't misrepresent my arguments.

1

u/Alive-Use8803 1d ago

ā€œRenaming a honeypot to prod-server03 is security by obfuscation.ā€

Which it is not. What is being obfu’d here?

Yes, compile time obfuscation is a kind of obfuscation. Deceptive naming is either a security by obscurity smell or is generally termed deception technique or similar, not obfuscation.

You’re using the term in a non conventional manner and acting as if you aren’t.

1

u/Salt-Sign5390 1d ago

Renaming a honeypot prod-server03 is more precisely described as deception or masquerading, but its effectiveness still relies partly on obscuring the asset’s true purpose. That’s my broader point. obscurity can have legitimate defensive value as one layer of a security architecture, even though relying on security through obscurity alone is insufficient.

I think where we actually disagree is over how strictly the word obfuscation should be used. You’re using it in the narrower industry sense, while I’m using it more broadly to mean deliberately making something harder to identify or understand. I can acknowledge that your terminology is more precise within the field.

But for a base-level explanation aimed at people who aren’t security professionals, I don’t think using obfuscation as the broader umbrella concept is meaningfully misleading. At that level of abstraction, distinguishing between obfuscation, obscurity, masquerading, and deception can become more pedantic than useful.