Home
About Us
Contact Us
Advertise
Facebook
Twitter
RSS Feed
Printable version
From the Editor: Don't Take Encryption for Granted
By Systems Management News Team
June 15, 2008 —
When the Debian team revealed in May that it had cryptography problems, many systems administrators found themselves regenerating and managing thousands of encryption keys. From a management standpoint, the biggest hassle was, likely, figuring out which keys were bad and where they all resided.
But for the end user, the whole debacle was likely ignored. When it comes to public key encryption, most end users have to have a VPN or keyed Web access set up for them. They don’t even know there’s encryption involved, let alone understand what an elliptic curve is.
These users are probably taking your security measures for granted. And, now that Internet encryption is an old and proven discipline, perhaps you’re taking your encryption for granted as well. Encryption can be a double-edged sword, however. If your system is locked down, and all your keys are 1024 bits or higher, it’s very likely that, if there’s a security breach, you’re not going to consider a successful brute force attack against those keys as your first culprit. Instead, it’s more likely that someone’s password has been stolen, a database has been compromised or a trojan has made its way onto a server.
Should security practitioners think this way? Probably not, but after years of solid and reliable encryption being available to anyone everywhere, it’s no wonder that crypto tends to be the last possible place people expect a failure. Blame vendors and open-source developers; it’s easy to spin the wheel and scramble things beyond recognition before sending them out into the wild.
And this is why the Debian failure has been such a massive nightmare: With the changing of just a few lines of code, millions of keys generated by thousands of users over the past two years have been completely vulnerable, and there’s been nary a clue. Even the best of cryptographers can’t tell if a bad random number generator was used just by looking at the key. And that’s the worst part about crypto vulnerabilities: They’re the sort of problem that can be hidden for years then pop up suddenly to reveal an entire infrastructure as vulnerable.
It’s unfortunate that the Debian team made this mistake, but perhaps, as a warning, it’s a good thing overall. We’d bet that no one who’s following this issue is going to take cryptography for granted anymore. As rightly they shouldn’t.
Related Search Term(s):
Security
,
Debian
Share this link:
http://www.sysmannews.com/link/32353
Related Articles
Metadata Security for SharePoint Adds Security Permissions
Titus Metadata Security for SharePoint allows permissions to be assigned based on the recipient's Active Directory properties
New Database Reporting Console Tracks Compliance
Application Security's Analytics 1.0 is used in conjunction with the company's DbProtect database security suite. It is based on Cognos' business intelligence suite and contains dashboards that cover compliance and security key performance indicators.
The Data Center: Security, Compliance Issues Holding Back the Clouds
Cloud computing is still gaining steam as a concept and practice in the industry. Acceptance of it is being hindered by flaws in its application and by lingering doubts to its effectiveness, things that can or will soon be addressed.
Add comment
Name*
Email*
Country
United States
Canada
Afghanistan
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua & Barbuda
Antilles, Netherlands
Arabia, Saudi
Argentina
Armenia
Aruba
Australia
Austria
Azerbaijan
Bahamas, The
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bermuda
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Brazil
British Virgin Islands
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Congo
Cook Islands
Costa Rica
Cote D'Ivoire
Croatia
Cuba
Cyprus
Czech Republic
Denmark
Djibouti
Dominica
Dominican Republic
East Timor (Timor-Leste)
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
Gabon
Gambia, the
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guinea
Guinea-Bissau
Guinea, Equatorial
Guyana
Haiti
Holland (see Netherlands)
Honduras
Hong Kong, (China)
Hungary
Iceland
India
Indonesia
Iran, Islamic Republic of
Iraq
Ireland
Israel
Italy
Jamaica
Japan
Jordan
Kazakhstan
Kenya
Kiribati
Korea (North)
Korea (South)
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libyan Arab Jamahiriya
Liechtenstein
Lithuania
Luxembourg
Macao, (China)
Macedonia, TFYR
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States of
Moldova, Republic of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar (ex-Burma)
Namibia
Nauru
Nepal
Netherlands
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Norway
Oman
Pakistan
Palau
Palestinian Territory
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russia (Russian Federation)
Rwanda
Saint Helena
Saint Kitts and Nevis
Saint Lucia
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia & Montenegro
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
Spain
Sri Lanka (ex-Ceilan)
Sudan
Suriname
Swaziland
Sweden
Switzerland
Syrian Arab Republic
Taiwan
Tajikistan
Tanzania, United Republic of
Thailand
Timor-Leste (East Timor)
Togo
Tokelau
Tonga
Trinidad & Tobago
Tunisia
Turkey
Turkmenistan
Turks and Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United Kingdom
Uruguay
Uzbekistan
Vanuatu
Vatican City State (Holy See)
Venezuela
VietNam
Virgin Islands, British
Virgin Islands, U.S.
Wallis and Futuna
Western Sahara
Yemen
Zambia
Zanzibar
Zimbabwe
[Not specified]
Comment
Preview