Arguably, most security is security through obscurity.
No password -> simple password -> complex password
Plaintext -> Caesar cypher -> Vernier cypher -> modern cyphers
40-bit crypto -> 56-bit crypto -> 128-bit crypto -> 256-bit crypto
0.0.0.0 network allow-list -> /24 network allow-list -> /32 (per host) network allow-list
allow by default -> deny by default
standard port -> non-standard port
We just add layers of obscurity until they add up to "enough" and don't grow into "beyond tedious".