I've taken to using static resources to link to files, along with custom content types. Then I can either just use the resource ID for the URL tags, or manipulate things with MIGx or some other TV. You can even use MIGXdb as a TV or as a CMP to manage your static resources, hiding them from the Resource Tree and only managing them from the TV/CMP. I lean towards a MIGXdb TV if there aren't going to be a lot of them, since that way I can have them organized by container resources, something like the Articles package does.
Since the only URL ever seen is the one to the static resource, your actual file location is hidden. You can point the static resource to files outside the web root, which is even more secure than just obfuscation.
You can see this in action on my own site here
http://sottwell.com/articles/wayfinder.html