"Security through obscurity is NOT bad.
Security ONLY through obscurity is bad (Kerckhoffs's Principle).
Security through obscurity, as an additional layer, is good!"
> virtually all cryptographic functions and authentication
I'm not sure if I got you. These protocols ideally introduce computational complexity, not the cognitive one. How do you define obscurity? The more complex (for understanding) system—the more bugs, which some malicious AI agent will find out at some point.
Security Through Obscurity Is NOT Bad - Mo Beigi
Why security through obscurity still matters: not as your only defence, but as a practical layer that raises attacker cost.