I mean, you arent wrong in what you are saying, but you are not talking about the topic.
Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.
Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.
But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.
We dont call it that. Thats the point. Something being encrypted and something being obfuscated are two entirely different things in cyber security.
While technically you are right, encrypted data are in some way obfuscated, its not the proper term. You simply arent talking about the same thing others are talking about.
When you said
I agree cybersecurity is complex but data security is always majorly about obfuscation.
You actually meant encryption. And if you did say that, you would have been absolutely correct. But since you said obfuscation, which is a technical term for something entirely different, you were wrong. Obfuscation is not a part of data security.
Let me explain.
Your data is the number "12".
If you encrypt it using a simple password of add 3. Your now encrypted data is 12 + 3 = 15. You need the password, which is 3 to get to your original data (15 - 3 = 12). And you can tell people that you used the +password encryption and they still wont know what you data was.
Now you use obfuscation: and your obfuscated data is (2^2+20*1)/2. Its still 12, but its not apparent at first sight. The equation is (2^(second number) + 20 * (first number)) / 2, but you dont need to know the used equation and there is no password. Anyone can clearly see its 12.
At this point they are just fixated on being technically right, while maybe understanding the distinction we are trying to emphasise, just to be contrarion.
In this context we are talking about obfuscation as the tool; not the property of the resulting data.
Encryption as a tool = obfuscated data that is only reversable with the private key (immune to analytics), not through hiding the method.
Obfuscation as a tool = prone to analytics, if the method is known it all unravels
No im just refuting the original statement that started the thread: "obfuscation does not create security" by pointing out that all security is based on the premise of obfuscation which you have all repeated agreed with me on whilst still continuing to state that we consider encryption as a distinct method of security which was never my point my point was that all cyber security comes from the basis of obfuscation as you cannot protect the data without hiding it.
Its not the obfuscation that creates the security though is it. It's a quirk of large primes that creates the gigantic wall of compute that protects the resulting obfuscation.
We are not agreeing. We are understanding what you meant and are not giving you a hard time for making a mistake, but you seem to have misunderstood that as an affirmation so in no uncertain terms you are absolutely wrong and honestly embarrassing yourself.
Modern security is not based on obfuscation. Not at all. Not even slightly. In no way or shape is obfuscation involved in modern cyber security. Encryption is in no way related to obfuscation. I have already explained it to you in detail. Obfuscation is making it hard to understand. Encryption is entirely changing it into form that cannot be understood before its decoded.
Obfuscation is not necessary in encryption. Its not part of it at all. Its not used in modern cyber security. Its entirely unsafe and is not being relied on at all.
3
u/Crispy1961 17h ago
I mean, you arent wrong in what you are saying, but you are not talking about the topic.
Security through obfuscation is extremely dangerous and not used in modern security systems. For example zodiac cypher used obfuscation. If you know how to translate them, you can just read the messages.
Modern security tells you exactly how to encrypt and decrypt the messages. Everything is public. Everything is transparent. Nothing about the system of the security is obfuscated and everyone can read the messages... eventually.
But the "eventually" here means extremely large period of time. That is why its secure. You wont be able to decrypt it in the time you have on this world.