>  	In the end, service obfuscation achieves nothing.  One of three
> things will still happen: the anklebiting scriptmonkeys will just bang
> away at it; automated intrusion agents (worms) won't give a good rip
> will still bang at it; and the truly skilled attacker will see right
> through it.  Thus, the net value of said service obfuscation is nil.

I think that this distinction between threats is very good. Obfuscation
helps in repelling the script kiddies and worms, but may not help
against targeted professional attacks. 

While I would not nullify obfuscation benefits, I think that the number
of targeted attacks is on the rise. For example, recent publications
suggest that the Vodafone/Paris Hilton hack was done by a group
researching the site for a year! (Even the actual entry to Hilton's
account, which seems to have been a result of "low tech" social
engineering would have resisted obfuscation). Another good example of
targeted attacks is the XSS driven phishing attacks flourishing this

Generally speaking, the visibility of automated attacks such as worms is
magnified due to their large spread, but the actual damage to a single
organization is relatively small. So while having a similar threat level
(higher risk but lower impact) as targeted attacks, they are much more
influential in decision makers mind.

