<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>obfuscator</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/default.aspx</link><description>.NET Obfuscator
.NET Code Obfuscation, Security and Protection</description><dc:language>en-US</dc:language><generator>CommunityServer 1.0 (Build: 1.0.1.50214)</generator><item><title>Microsoft's Software Licensing and Protection and Dotfuscator</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2007/07/25/Microsofts_Licensing_and_Protection_Services_and_Dotfuscator_Integration.aspx</link><pubDate>Wed, 25 Jul 2007 17:56:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:270825</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/270825.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=270825</wfw:commentRss><description>First obfuscation and instrumentation solution offers .NET application protection, analytics, licensing and activation services through the integration of Dotfuscator, SO-signal, and Microsoft's SLP Services....(&lt;a href="http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2007/07/25/Microsofts_Licensing_and_Protection_Services_and_Dotfuscator_Integration.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=270825" width="1" height="1"&gt;</description></item><item><title>The fourth dimension of enterprise obfuscation is tamper notification</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2007/06/21/250179.aspx</link><pubDate>Thu, 21 Jun 2007 14:23:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:250179</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/250179.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=250179</wfw:commentRss><description>If you invest in fire prevention – don’t you also want fire detection?   This begs the question “if an organization cares enough to invest time and resources into reverse engineering prevention, wouldn’t that same organization benefit from reverse engineering detection?” 

&lt;p&gt;Those who lose sight of the fact that the organizing principle behind obfuscation is the requirement to manage risk also undervalue the importance of the obfuscation process. The result is a one dimensional view of obfuscation as a finite set of technology limited to the transformation of application binaries. However, the emergence of Service Oriented Architecture (SOA) and Software as a Service (SaaS) combined with a growing recognition that the most effective IT controls must bridge the development lifecycle and operations management has made it possible, for the first time, to prevent reverse engineering and to detect tampering when it should occur.&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=250179" width="1" height="1"&gt;</description></item><item><title>Attend Free Webinar on Enterprise Risk Management and Obfuscation</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2006/04/17/136833.aspx</link><pubDate>Mon, 17 Apr 2006 14:41:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:136833</guid><dc:creator>obfuscator</dc:creator><slash:comments>1</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/136833.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=136833</wfw:commentRss><description>&lt;P&gt;&lt;TR&gt;&lt;TD align="right"&gt;&lt;STRONG&gt;Sign up for the Event:&lt;/STRONG&gt;&lt;/TD&gt; &lt;TD&gt;&lt;A href="https://preemptive.webex.com/mw0202l/mywebex/default.do?siteurl=preemptive"&gt;Obfuscation, IT Governance and Enterprise Risk Management&lt;/TD&gt; &lt;TD align="right" rowspan="8"&gt;&amp;nbsp;&lt;/TD&gt; &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="right"&gt;&lt;STRONG&gt;Date and Time:&lt;/STRONG&gt;&lt;/TD&gt; &lt;TD&gt;Monday, April 24, 2006 1:00 pm&lt;BR&gt;Eastern Daylight Time (GMT -04:00, New York) &lt;/P&gt;
&lt;P&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="right"&gt;&lt;STRONG&gt;Duration:&lt;/STRONG&gt;&lt;/TD&gt; &lt;TD&gt;30 minutes&lt;/TD&gt; &lt;/P&gt;
&lt;P&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="right"&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;/TD&gt; &lt;TD&gt;Attendees will leave with a clear understanding of:&lt;BR&gt;-the role of obfuscation as an effective control for application security, access control, IP protection in the context of broader IT governance and enterprise risk management frameworks.&lt;BR&gt;-a basis to assess the cost/benefit of including obfuscation as a component of your ongoing governance, risk and compliance programs.&lt;/P&gt;
&lt;P&gt;For more general info on see:&amp;nbsp;&lt;A href="http://www.preemptive.com"&gt;Java and .NET obfuscation and IP Protection&lt;/A&gt;&lt;/P&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=136833" width="1" height="1"&gt;</description></item><item><title>Register for a free Webinar</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2006/03/20/136146.aspx</link><pubDate>Mon, 20 Mar 2006 18:58:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:136146</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/136146.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=136146</wfw:commentRss><description>Register for a webinar on the "Essential Characteristics of an Effective Obfuscation Process".  &lt;br&gt;&lt;br&gt;https://preemptive.webex.com/mw0202l/mywebex/default.do?siteurl=preemptive&lt;br&gt;&lt;br&gt;Date and Time: &amp;nbsp;&amp;nbsp; &amp;nbsp;Monday, March 27, 2006 1:00 pm&lt;br&gt;Eastern Standard Time (GMT -05:00, New York) Change time zone&lt;br&gt;Panelist(s) Info: &amp;nbsp;&amp;nbsp; &amp;nbsp;Sebastian Holst and Gabriel Torok&lt;br&gt;Duration: &amp;nbsp;&amp;nbsp; &amp;nbsp;30 minutes&lt;br&gt;Description: &amp;nbsp;&amp;nbsp; &amp;nbsp;Attendees will leave with a clear understanding of:&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Benefits and potential consequences inherent in the variety of obfuscation transformations available today.&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Development lifecycle opportunities and process requirements for integrating obfuscation with special attention given to continuous integration, distributed development, quality and manufacturing and patch management.&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=136146" width="1" height="1"&gt;</description></item><item><title>Obfuscation: Algorithm or Process?</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2006/02/03/135031.aspx</link><pubDate>Fri, 03 Feb 2006 15:20:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:135031</guid><dc:creator>obfuscator</dc:creator><slash:comments>2</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/135031.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=135031</wfw:commentRss><description>&lt;span&gt;

Is Obfuscation an algorithm or process?

Just like encryption, obfuscation should not be viewed in terms of just an algorithm.
The Encryption process requires key management, decryption, etc. Similarly, the obfuscation process should
address issues such as debugging, patch management, distributed development,
support and QA functions. 
&lt;br&gt;
An &lt;a href="http://www.preemptive.com/obfuscator.html"&gt;obfuscation solution&lt;/a&gt; addresses all of these issues by embedding the obfuscation algorithm into a process that is itself
integrated into the broader application development lifecycle. An
obfuscation solution should include&lt;br&gt;
&lt;br&gt;
&lt;li&gt;An integrated and distributed “lucidator”&lt;/li&gt;
A &lt;a href="http://www.preemptive.com/products/Lucidator.html"&gt;lucidator&lt;/a&gt; can reverse much of the obfuscation process to support
debugging. Of course it must be a secure process that cannot run
outside of its environment or on unauthorized code. Integration with
the obfuscator supports unit testing and distribution enables debugging
and support outside of the developer community that uses the obfuscator.&lt;br&gt;
&lt;br&gt;
&lt;li&gt;Declarative obfuscation&lt;/li&gt;
Developers are able to markup their code using attributes that define
the level of obfuscation to be applied at a granular level maximizing
developer control.&lt;br&gt;
&lt;br&gt;
&lt;li&gt;Incremental obfuscation&lt;/li&gt;
Obfuscate patches ensuring that they can be applied in the field against previously obfuscated code.&lt;br&gt;
&lt;br&gt;
&lt;li&gt;Integration into your IDE&lt;/li&gt;
Managing and automating the obfuscation process within your common IDE
simplifies and secures this process within the broader development
lifecycle supporting continuous integration.&lt;br&gt;

Make sure that when you look for an obfuscator, you are really looking a complete obfuscation solution.

&lt;/span&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=135031" width="1" height="1"&gt;</description></item><item><title>The Software Security Summit</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2006/01/24/134905.aspx</link><pubDate>Tue, 24 Jan 2006 21:48:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:134905</guid><dc:creator>obfuscator</dc:creator><slash:comments>2</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/134905.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=134905</wfw:commentRss><description>&lt;FONT&gt;
&lt;P&gt;If you are going to the &lt;A href="http://www.s-3con.com/"&gt;Software Security Summit&amp;nbsp;&lt;/A&gt;stop by PreEmptive's booth and attend our talk: TITLE: Binary protection: alignment with IT Governance, IP policies and effective risk management&lt;/P&gt;
&lt;P&gt;The role of source code protection is well-understood in the context of IP management and security. Assuming that a reasonable set of controls are in place as a function of an effective IT governance program, most organizations are under the impression that they are managing risks associated with the loss of intellectual property, loss of revenue due to piracy, malicious attacks on operations and, by extension, reputation.&lt;/P&gt;
&lt;P&gt;However, the richness and flexibility of modern runtime platforms such as Java and .NET have the side effect of simplifying the reconstruction of source code via access to associated binaries. As a result, organizations must either extend source code controls to their executables or establish an alternate set of compensating controls to mitigate these risks. Typically, it is not practical to manage executables in the same fashion as source due to the obvious difference in use. Therefore, an alternate strategy is required to provide a reliable mitigation of risk. Program &lt;A href="http://www.preemptive.com"&gt;obfuscation &lt;/A&gt;offers one such strategy. This session will discuss the different types of obfuscation technologies available, some of the issues that arise when using an obfuscator, and steps you can take to make obfuscation a seamless part of a secure development cycle.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.s-3con.com/"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=134905" width="1" height="1"&gt;</description></item><item><title>Thoughts on .NET Obfuscation, Encryption and Coverting to Native</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2005/12/22/134433.aspx</link><pubDate>Thu, 22 Dec 2005 14:17:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:134433</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/134433.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=134433</wfw:commentRss><description>Tools that rely on encryption to protect an application suffer from has
a critical flaw:&amp;nbsp; the app needs to be decrypted on the client
before being fed to the runtime.&amp;nbsp; A hacker can potentially recover
a decrypted version of the image, and that image (even though it's
native) still contains the metadata.&lt;br&gt;
&lt;br&gt;
With obfuscation, critical information (useful to human readers of the
code), is removed before the app is delivered to unsecured
clients.&amp;nbsp; You can't crack it if it isn't there.&lt;br&gt;
&lt;br&gt;
Tools that convert a .NET app into native code defeat the main ideas behind .NET.&lt;br&gt;
The idea of .NET is that applications will be able to run on any platform.&lt;br&gt;
Have you tried to run one a native app on a 64-bit version of the .NET
framework? I don t think it will work. I do not think it is even
possible for native code to work cross platform. Any what about
PocketPCs?&lt;br&gt;
&lt;br&gt;
Also, this code is no longer managed because managed means 100% IL. And
there may be a big difference in security between this code, and
managed code.&lt;br&gt;
&lt;br&gt;
Lastly, please, please test a tool that claims to turn your .NET app
into a native on your application before buying it. I have had many
people tell me that their app does not work exactly the same after
being run through a tool that converts it to a native one. &lt;br&gt;
&lt;br&gt;
&lt;a href="www.preemptive.com"&gt;.NET Obfuscation&lt;/a&gt; is a safer and more robust solution. It does not
violate the intent of .NET and properly applied, it significantly
raises the bar against reverse engineering. &lt;br&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=134433" width="1" height="1"&gt;</description></item><item><title>Visual Studio 2005 is ready to launch</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2005/11/03/133553.aspx</link><pubDate>Thu, 03 Nov 2005 18:25:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:133553</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/133553.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=133553</wfw:commentRss><description>&lt;font&gt; There is lots of excitment surrounding the VS 2005/&lt;/font&gt;&lt;font&gt;SQL Server 2005&lt;/font&gt;&lt;font&gt; launch in San Francisco on November 7, 2005.&lt;/font&gt;&lt;font&gt;&lt;br&gt;A link to the event is here http://www.microsoft.com/events/2005launchevents/default.mspx&lt;br&gt;
&lt;br&gt;
We will be at the event and of course are happy that Dotfuscator Community Edition is shipping inside &lt;a href="http://www.prdomain.com/companies/m/microsoft/news_releases/200407jul/pr_microsoft_20040719.htm"&gt;Visual Studio 2005.&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Because, we are in the box - &lt;br&gt;
&lt;a href="www.preemptive.com"&gt;Dotfuscator&lt;/a&gt; Professional Edition has had &lt;/font&gt;&lt;span class="list"&gt;support for .Net Framework version 2.0 (beta) and Visual Studio 
2005 (beta) since April and &lt;br&gt;
Support for the final release of &lt;/span&gt;&lt;span class="list"&gt;.Net Framework version 2.0 and Visual Studio 
2005 over a month ago.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/span&gt;&lt;font&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
 &lt;/font&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=133553" width="1" height="1"&gt;</description></item><item><title>Welcome to the Obfuscator Blog -- So what is it?</title><link>http://www.dotnetjunkies.com/WebLog/obfuscator/archive/2005/10/20/133327.aspx</link><pubDate>Thu, 20 Oct 2005 21:25:00 GMT</pubDate><guid isPermaLink="false">58df7014-fd75-437c-9641-150997716d1c:133327</guid><dc:creator>obfuscator</dc:creator><slash:comments>0</slash:comments><comments>http://www.dotnetjunkies.com/WebLog/obfuscator/comments/133327.aspx</comments><wfw:commentRss>http://www.dotnetjunkies.com/WebLog/obfuscator/commentrss.aspx?PostID=133327</wfw:commentRss><description>&lt;P&gt;An &lt;A href="http://www.preemptive.com/"&gt;Obfuscator&lt;/A&gt; is the business of shrouding the facts. It is not encryption, but in the context of .NET code, it might be better. Although encryption can make your assembly completely unreadable, this methodology suffered from a classic encryption flaw, it needed to keep the decryption-key with the encrypted data. So, an automated utility could be created to decrypt the code and put it out to disk. Once that happens the fully unencrypted, unobfuscated code is in clear view.&lt;/P&gt;
&lt;P&gt;As another comparison, we could compare encryption to locking a ten item meal into a lockbox. Only the intended diner (i.e. the CLR) has the key and we don't want anyone else to know what he or she is going to eat. Unfortunately, if someone can pick the lock (or find the key hidden on the bottom of the box), the food is in plain view. Obfuscation works more like putting the six-item meal into a blender and sending it to the diner in a baggie. Sure everyone can see the food in transit, but besides a lucky pea pod or some chicken-colored goop, they don't know what the original meal consists of. The diner still gets the intended delivery and the meal still provides the same nutritional value as it did before (luckily, CLRs aren't picky about taste). The trick of an obfuscator is to confuse observers, while still giving the CLR the same delivery.&lt;/P&gt;
&lt;P&gt;Without argument, obfuscation (or even encryption) is not 100 percent protection. Even compiled C++ is disassembleable. If a hacker is perseverant enough, they can find the meaning of your code. The goal of obfuscation is to make the reverse engineering process extremely time consuming and painful so that it not worth the effort. The goal is to stop all casual hackers and as many serious hackers as possible.&lt;/P&gt;
&lt;P&gt;Obfuscation removes context from compiled code that humans (and reverse-engineering tools) would use to decipher the code's meaning. The trick is to remove this context from evil intentions while retaining complete execution integrity with the original program. &lt;/P&gt;
&lt;P&gt;Want to try obfuscation...&lt;/P&gt;
&lt;P&gt;Fire up Visual Studio, click on the tools menu and select Dotfuscator Community Edition.&lt;/P&gt;
&lt;P&gt;Dotfuscator is available in three editions and you can learn more about the differences &lt;A href="http://www.preemptive.com/products/dotfuscator/Editions.html"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://www.dotnetjunkies.com/WebLog/aggbug.aspx?PostID=133327" width="1" height="1"&gt;</description></item></channel></rss>