How does rclone obfuscate client secrets?

All those ways are just obfuscating the client key though, right? Doing an ecrypted config would be the same too, correct? (I'd still have to decrypt the config client-side since everything has to be done on the client)