Identifier Renaming: The First Layer, Never the Last
Every technique module in this course follows the same honest format: what the transform does, a hand-rolled before and after you can actually read, why it raises the attacker's cost, and exactly where it stops helping. We start with the simplest transform there is.
Picture a recipe where every ingredient is labeled plainly: flour, sugar, salt. Now imagine someone relabels them jar1, jar2, jar3, consistently, everywhere they appear. The recipe still makes the exact same cake, but you can no longer tell at a glance what goes in. That relabeling is identifier renaming. It removes the helpful names without changing a single step of the cooking.
What renaming does
Well-written code names things after what they mean: calculateDiscount, playerHealth, isAdmin. Those names are pure gift to a reader, they explain the program without a single comment. Identifier renaming walks the whole program, builds a map from every function, variable, and parameter to a short meaningless token, and rewrites every reference consistently. The logic is untouched. The documentation that names provided is gone.
function calculateDiscount(price, percent) {
const saved = price * (percent / 100);
return price - saved;
}
console.log(calculateDiscount(200, 15));function _0x1a(_0x2b, _0x3c) {
const _0x4d = _0x2b * (_0x3c / 100);
return _0x2b - _0x4d;
}
console.log(_0x1a(200, 15));Now do it yourself, one name at a time. This is a live rename pass over a real syntax tree in the academy's teaching language. Drag the slider and watch each name disappear from the definition and every use at once, while the program's behaviour stays byte-for-byte identical.
One subtlety separates a correct renamer from a broken one: scope. The same short name can safely be reused in different scopes, but a variable captured by an inner function must keep pointing at the same thing after renaming. Getting this wrong silently changes behaviour, which is why scope-aware renaming is table stakes for any serious tool.
Two failure modes make scope-awareness non-negotiable. Capture: renaming two distinct variables to the same token inside overlapping scopes merges them, silently corrupting results. Collision with reachable names: renaming a field or method that some other code resolves by its textual name (reflection, string-keyed lookup, serialization keys) breaks the lookup, because that consumer never went through the rename map. A correct renamer therefore treats a name as renamable only when every reference to it is statically visible in the same unit being transformed, and freezes anything that could be reached dynamically. The output looking scrambled tells you nothing about whether this analysis was done right, which is why renaming bugs are classic silent-wrong bugs.
Why it raises cost
A reader can no longer skim the file and understand intent from names alone. To rebuild what price and percent meant, they have to trace actual values through the code, which is slow, attention-hungry work. Multiplied over thousands of identifiers in a real program, that is hours of tedium added before any real analysis starts.
Where it stops helping
The structure is identical to the original. The strings are still readable. The control flow still tells its story top to bottom. A determined reader simply re-labels identifiers as they figure them out, rebuilding your documentation one name at a time, and modern decompilers and AI assistants auto-suggest plausible names from context with unsettling accuracy. Renaming alone buys minutes against a professional, not safety.
Rule of thumb: if you can still read the logic in the output, it was renamed, not protected. Renaming is a fine first layer precisely because it is cheap, and a scam when sold as the whole product.
Renaming vs minification
Minifiers (like the ones in every JavaScript build chain) also shorten names, but their goal is smaller files, not confusion, and their output is so uniform that pretty-printers and unminifiers reverse the cosmetic damage instantly. If a vendor's "obfuscation" output looks like ordinary minified code, you are looking at a compression tool wearing a security costume. Real obfuscation stacks renaming with the string, constant, control-flow, and virtualization layers covered in the rest of this module.
Frequently asked questions
Is minified code obfuscated?
Not meaningfully. Minification shortens names and strips whitespace for file size, and standard tooling reverses the formatting instantly. It offers near-zero resistance to a reader who cares. Obfuscation aims to raise reading cost and uses many layers beyond renaming.
Can renamed code be deobfuscated automatically?
The original names cannot be recovered (they are genuinely gone), but tools and AI assistants can suggest plausible replacement names from context, which restores much of the readability. That is exactly why renaming is only useful as one layer among several.
Does renaming affect performance?
No. Names are for humans; the runtime does not care what a variable is called. Renaming is the one transform that is essentially free at runtime, and it can even shrink file size.