
Originally Posted by
Cutriss
Depends on the obfuscation method but I don't think you're seriously evaluating the statements. See my example above. I think you're considering the probability that obfuscation makes a target stand out by trying not to stand out (example - blank SSIDs), and that's not really going to my example at all.
Also your best case seems to basically take the position of O(29385902385923n) = O(n), which masks the fact that in this case we want to increase ω(n) (from memory here, forgive me if I'm using the wrong notation) so that we reduce the chances of a successful attack being carried out.
Don't confuse this with things like security theater. Techniques like port-knocking (however flawed they may be) don't even register on the scale of impact to the authorized user, but add a few orders of magnitude to the complexity for the random attacker, and without foreknowledge of the layer, make a target appear less vulnerable.
Do they stop a dedicated, focused attack? Eventually not, but it increases the likelihood of being able to see (and stop) the attack in progress.
If you'd like to continue to debate this I'm welcome it. If you'd rather just make blanket assumptions on the Internet and pretend you've always been right, then I'll just move on.