Information Security in Open Systems

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    1 Favorite

    Information Security in Open Systems - Presentation Transcript

    1. Information Security in Open Systems Paula Valença pvalenca@di.uminho.pt
    2. What this will not be about... • ... a study of security and cryptography in OpenBSD... • ... I know too little to make any serious comment on the subject
    3. What this will not be about... • ... a study of security and cryptography in OpenBSD... • ... I know too little to make any serious comment on the subject
    4. What this will not be about • curves suitable for identity based cryptography • algebraic attacks on AES • breaks on SHA-1, SHA-0, MD5
    5. What this will not be about • curves suitable for identity based cryptography • algebraic attacks on AES • breaks on SHA-1, SHA-0, MD5
    6. What this will be about • A light chat regarding the security paradigm and state of situation, from the academia to software developers and users • WARNING... I am at the most abstract corner you can think of
    7. Things that get me thinking • “So say I want a good security software - what should I choose / where should I look at?” • “How do I know that it is safe to use my credit card with site X?” • “... does that mean it’s not safe? Have they broken cryptography?”
    8. The Babel Tower The researchers The specs writers The developers The admins The users
    9. The Babel Tower The researchers The specs writers The developers The admins The users
    10. Things slip through the creases • Phong Nguyen’s look at GPG in 2003 revealed compromised ElGamal keys (when sign+encrypt was used) • Arnold Yau and Kenny Patterson’s attacks on IPsec via lack of authentication/integrity protection
    11. Are attacks realistic? • For many it’s debatable. Cryptographers look at the worst case scenario... take “chosen ciphertext attacks”, for example • And then comes efficiency, flexibility, backward-compatibility • ... confusing warnings... • ... still, Murphy’s law
    12. Good things about open systems • audit, peer-reviews, source code availability... • does not necessarily mean that it is • ... and more important still, by the “experts”
    13. the present and future • Information security is turning more and more into management that IT: protocols, directives • ... which are not always clear (take IPsec series of RFCs, for example) • Schneier’s recent article speaks of a shift from apps to services
    14. Questions? More importantly, discussion...

    + Paula ValencaPaula Valenca, 5 months ago

    custom

    468 views, 1 favs, 0 embeds more stats

    OpenBSD meeting (invited), Coimbra 2007

    It was m more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 468
      • 468 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 18
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories