Research

Bot Fighting 201. Part 4. Obfuscating Protocols. Versioning.

January 16, 2018 by “No Bugs” Bunny

Obfuscating Protocols

Quote:

we can handle several Client versions (each with its own obfuscation) with the very same Server.

Another Quote:

Then, if/when a zero-day bug is encountered in TLS – our obfuscation does provide additional protection even before the attacker can reach the code with that zero-day vulnerability

Filed under: Book: D&D of MOGs1st beta of Vol. VII-IXOn.SecurityFraud PreventionResearch

Read more

Advocating "Obscurity Pockets" Part III. Code Obfuscation Basics.

February 14, 2017 by “No Bugs” Bunny

Obfuscating Code

Quote:

C++ is by far the king when it comes to producing obfuscated code.

Another Quote:

inlines and C++ templates are helping to obfuscate things very efficiently

Filed under: On.SecurityResearch

Tagged With: C/C++crazy stuff
Read more

Advocating “Obscurity Pockets” as a Complement to Security. Part II. Deployment Scenarios, More Crypto-Primitives, and Obscurity-Pocket-As-Security

February 7, 2017 by “No Bugs” Bunny

Hacker hit by Obscurity

Quote:

In other words – such an Obscured RNG would protect us from Debian RNG disaster(!)

Another Quote:

such a protocol (if properly deployed on the Server Side) – would defeat Heartbleed too (even if all the details of the Client are known)

Filed under: On.SecurityResearch

Tagged With: crazy stuffCrypto
Read more

Advocating “Obscurity Pockets” as a Complement to Security. Part I. Definition and Benefits.

January 31, 2017 by “No Bugs” Bunny

He was preaching Security-by-Obscurity

Quote:

In a hypothetical world where attackers would need to create a unique attack script for each system attacked – such an economy would be a non-starter.

Another Quote:

If all the people would be the same - pandemics such as Black Death would easily take the whole humankind down; it is diversity among humans which allowed us to survive.

Filed under: On.SecurityResearch

Tagged With: crazy stuffCrypto
Read more