Bitcoin Forum
May 22, 2024, 05:52:17 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: RSA Conference 2013: Experts Say It's Time to Prepare for a 'Post-Crypto' World  (Read 1627 times)
herzmeister (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1007



View Profile WWW
February 27, 2013, 10:46:04 PM
 #1

https://threatpost.com/en_us/blogs/rsa-conference-2013-experts-say-its-time-prepare-post-crypto-world-022613

Quote
SAN FRANCISCO--In the current climate of continuous attacks and intrusions by APT crews, government-sponsored groups and others organizations, cryptography is becoming less and less important and defenders need to start thinking about new ways to protect data on systems that they assume are compromised, one of the fathers of public-key cryptography said Tuesday. Adi Shamir, who helped design the original RSA algorithm, said that security experts should be preparing for a "post-cryptography" world.

"I definitely believe that cryptography is becoming less important. In effect, even the most secure computer systems in the most isolated locations have been penetrated over the last couple of years by a series of APTs and other advanced attacks," Shamir, of the Weizmann Institute of Science in Israel, said during the Cryptographers' Panel session at the RSA Conference here today.

"We should rethink how we protect ourselves. Traditionally we have thought about two lines of defense. The first was to prevent the insertion of the APT with antivirus and other defenses. The second was to detect the activity of the APT once it's there. But recent history has shown us that the APT can survive both of these defenses and operate for several years."



Shamir, who shared the panel with Ron Rivest of MIT, Dan Boneh of Stanford University, Whitfield Diffie of ICANN and Ari Juels of RSA Labs, said that the continued assaults on corporate and government networks by sophisticated attackers in recent years has become the most important development in the security world. The time, he said, has come for security researchers and others involved in defending networks to look for methods other than cryptography that are capable of securing their sensitive data.

"It's very hard to use cryptography effectively if you assume an APT is watching everything on a system," Shamir said. "We need to think about security in a post-cryptography world."

One way to help shore up defenses would be to improve--or replace--the existing certificate authority infrastructure, the panelists said. The recent spate of attacks on CAs such as Comodo, DigiNotar and others has shown the inherent weaknesses in that system and there needs to be some serious work done on what can be done to fix it, they said.

"We need a PKI where people can specify who they want to trust, and we don't have that," said Rivest, another of the co-authors of the RSA algorithm. "We really need a PKI that not only is flexible in the sense that the relying party specifies what they trust but also in the sense of being able to tolerate failures, or perhaps government-mandated failures. We still have a very fragile and pollyanna-ish approach to PKI. We need to have a more robust outlook on that."

Shamir pointed to the incident recently in which TurkTrust, a Turkish CA, was found to have issued subordinate certificates for Google domains to two separate parties, one of which was a Turkish government contractor. He said he wouldn't be surprised to see other such incidents crop up.

"I think you will see more and more events like this, where a CA under pressure from a government will behave in strange ways," he said. "It brings into question whether the basis of security, the PKI infrastructure, is under severe strain."



https://localbitcoins.com/?ch=80k | BTC: 1LJvmd1iLi199eY7EVKtNQRW3LqZi8ZmmB
herzmeister (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1007



View Profile WWW
February 27, 2013, 10:46:24 PM
 #2

bye bye Bitcoin, it was nice knowing you.  Cry

https://localbitcoins.com/?ch=80k | BTC: 1LJvmd1iLi199eY7EVKtNQRW3LqZi8ZmmB
tpantlik
Full Member
***
Offline Offline

Activity: 136
Merit: 100


View Profile
February 27, 2013, 10:52:57 PM
 #3

Yeah, the last words on broken pki should be written on stone - or blockchain  Wink

Gods sent us a powerful tool - cryptography - to fight with those who are trying to exploit us. USE IT!!
Sukrim
Legendary
*
Offline Offline

Activity: 2618
Merit: 1006


View Profile
February 27, 2013, 10:57:33 PM
 #4

Their point is that computers are getting so insecure that it doesn't matter if they communicate encrypted or not - not that crypto gets broken.

E.g. somebody hosting a wallet on a server not at home makes it easy for the hoster to spy on that. As long as security measures are followed, your coins are safe too.

It kinda boils down to: "You can't trust the others to handle their stuff properly and it gets harder and harder for you to handle your own stuff."

https://www.coinlend.org <-- automated lending at various exchanges.
https://www.bitfinex.com <-- Trade BTC for other currencies and vice versa.
Scrat Acorns
Sr. Member
****
Offline Offline

Activity: 293
Merit: 250



View Profile
February 27, 2013, 11:05:21 PM
 #5

Video here: http://www.youtube.com/watch?v=eKhudJCGoJc
cypherdoc
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
February 27, 2013, 11:22:09 PM
 #6

Their point is that computers are getting so insecure that it doesn't matter if they communicate encrypted or not - not that crypto gets broken.

E.g. somebody hosting a wallet on a server not at home makes it easy for the hoster to spy on that. As long as security measures are followed, your coins are safe too.

It kinda boils down to: "You can't trust the others to handle their stuff properly and it gets harder and harder for you to handle your own stuff."

yes.

"We need a PKI where people can specify who they want to trust, and we don't have that," said Rivest, another of the co-authors of the RSA algorithm. "We really need a PKI that not only is flexible in the sense that the relying party specifies what they trust but also in the sense of being able to tolerate failures, or perhaps government-mandated failures. We still have a very fragile and pollyanna-ish approach to PKI. We need to have a more robust outlook on that."
Doctor Mushies
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
February 27, 2013, 11:25:34 PM
 #7

People like feeling they are protected, people feel they are safe, people trust other people far too much, and cryptography is 100% necessary for the world to advance.
TooCasual
Member
**
Offline Offline

Activity: 114
Merit: 10


You can't be Serious?!?


View Profile
February 27, 2013, 11:26:48 PM
Last edit: February 27, 2013, 11:37:21 PM by TooCasual
 #8

Post crypto world?  Replaced with what?  ...To say such statement is idiocy.

Maybe just going back to paper and punch-cards? LOL. No computers?  Back to the dark ages!  Unplug the Internet! haha

Most vulnerabilities are from compromised systems and stolen information (passwords etc.)

Crypto just has to grow with current technology.  Well most government institutions, universities, large corporations probably do NOT "upgrade" their security technology often enough as it is a major cost...

Anyways, cryptography must always be exponentially ahead of the curve.  Audited and updated yearly.

Use larger key pairs and passwords over 4096bit+.  Hasn't anyone ever heard of or use www.openbsd.org?  Why would anyone NOT use that for their servers?

TC
Bitobsessed
Sr. Member
****
Offline Offline

Activity: 291
Merit: 250



View Profile
February 27, 2013, 11:34:07 PM
 #9

Just throwing this out there but could it be replaced by quantum networks and quantum communication?  This technology is in its infancy but could explode over the next 10-20 years if it develops.  Our tech is expanding faster than we can even keep up.

http://www.sciencedaily.com/releases/2012/04/120411161604.htm
tpantlik
Full Member
***
Offline Offline

Activity: 136
Merit: 100


View Profile
February 28, 2013, 07:06:33 AM
Last edit: February 28, 2013, 08:29:48 AM by tpantlik
 #10

Hasn't anyone ever heard of or use www.openbsd.org?  Why would anyone NOT use that for their servers?

Yeah, we know and use BSD, but even with this secure unix, you are relying on other people – http://bsd.slashdot.org/story/10/12/15/004235/fbi-alleged-to-have-backdoored-openbsds-ipsec-stack

It's all about trust. We, the bitcoiners, know it.  Smiley

Gods sent us a powerful tool - cryptography - to fight with those who are trying to exploit us. USE IT!!
Timo Y
Legendary
*
Offline Offline

Activity: 938
Merit: 1001


bitcoin - the aerogel of money


View Profile
February 28, 2013, 09:20:56 AM
 #11

I think that 'Post-Crypto' in the context of this talk doesn't mean abolishing crypto entirely, but rather to stop relying on crypto for certain tasks.

Private keys are only effective if they are stored in private places, but on the internet nothing is truly private because every system has holes and leaks.  Crypto alone can't be used to create the private places that it relies on, so we need something else, like Trusted Computing, to do that job.  I think that's the gist of it.


GPG ID: FA868D77   bitcoin-otc:forever-d
Timo Y
Legendary
*
Offline Offline

Activity: 938
Merit: 1001


bitcoin - the aerogel of money


View Profile
February 28, 2013, 09:36:19 AM
 #12

Just throwing this out there but could it be replaced by quantum networks and quantum communication?  This technology is in its infancy but could explode over the next 10-20 years if it develops.  Our tech is expanding faster than we can even keep up.

http://www.sciencedaily.com/releases/2012/04/120411161604.htm

The only difference between quantum cryptography and classical cryptography is that quantum cryptography is (allegedly) provably unbreakable and classical cryptography just hard to break.

However, quantum cryptography doesn't solve the fundamental problems discussed in the OP: Knowing who to trust and hiding your private keys.

GPG ID: FA868D77   bitcoin-otc:forever-d
nwbitcoin
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


You are a geek if you are too early to the party!


View Profile WWW
February 28, 2013, 09:42:07 AM
 #13

Read between the lines!

the hash table script kiddie is going to get you - Give us a job and it won't happen!

Smiley


Crypto is working so well, these people are looking for a new gig.  Their skills are not as much in demand as they were, so they are talking about a new threat.  This threat is so big that people will turn to them to fix it! They are back in work, and the scare factor of the new threat is toned down - and problem is never fixed enough to stop!

The problem for all security is that it needs to be upgraded as technology gets better.  Where 128 bit was great in the 90s, 1048 bit is the way forward for the 2020s and eventually we will have quantum crypto that will sample your dna as you breathe on the screen to enable your wallet!

However, if you do not have security policies in place, which you religiously follow, you will lose everything - and that is the post crypto world!

Simples!

*Image Removed*
I use Localbitcoins to sell bitcoins for GBP by bank transfer!
interlagos
Hero Member
*****
Offline Offline

Activity: 496
Merit: 500


View Profile
February 28, 2013, 10:29:43 AM
 #14

The problem with security is not in a cryptography itself (yet), but in the fact that people are unable to protect their secret keys and passwords.

I bet much more secure authentication mechanizm would be for client to register its public key with the server and for the server to issue one-time strings that the client would need to sign with its private key stored in a air-gapped USB hardware gadget (like those USB BItcoin hardware wallets in development). The server can then check if signature is valid against client's public key.

At least trojans and keyloggers won't have a chance against such system.
Littleshop
Legendary
*
Offline Offline

Activity: 1386
Merit: 1003



View Profile WWW
February 28, 2013, 01:16:53 PM
 #15

Someone just wanted to say "post-crypto" like "post-pc era" and then figured out how to make a speach around it.  The media then picked it up because it looks interesting. 

Nothing about what is really happening in the world makes me think we are going "post-crypto" world, to the contrary I think the use of cryptography will continue to expand. 

luv2drnkbr
Hero Member
*****
Offline Offline

Activity: 793
Merit: 1016



View Profile
February 28, 2013, 01:36:12 PM
 #16

The only difference between quantum cryptography and classical cryptography is that quantum cryptography is (allegedly) provably unbreakable and classical cryptography just hard to break.

Why is this?  I don't know anything about QM and only a little about crypto-- I'm assuming that somehow QM crypto can have an infinite keyspace, and that's how it's provably unbreakable, but that's just a wild-ass guess.  Do you have more information on your statement?  It intrigues me!

nwbitcoin
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


You are a geek if you are too early to the party!


View Profile WWW
February 28, 2013, 04:23:20 PM
 #17

The only difference between quantum cryptography and classical cryptography is that quantum cryptography is (allegedly) provably unbreakable and classical cryptography just hard to break.

Why is this?  I don't know anything about QM and only a little about crypto-- I'm assuming that somehow QM crypto can have an infinite keyspace, and that's how it's provably unbreakable, but that's just a wild-ass guess.  Do you have more information on your statement?  It intrigues me!

Quantum Cryptography works on the quantum physics theory that states that a thing can be one thing or another depending on when you look at it.  Its better explained here - http://en.wikipedia.org/wiki/Schr%C3%B6dinger's_cat

The point is that eventually, we will have crypto that is so complex that it will takes years to break.  What this theory doesn't take into consideration is that the tools for breaking them also gets better, so we end up at a stalemate - which suits the people at RSA just fine, as it keeps them all in a job! Wink

*Image Removed*
I use Localbitcoins to sell bitcoins for GBP by bank transfer!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!