Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Crypto Strikes Back!

Loading...

Sign in or sign up now!
10,959
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Aug 6, 2009

Google Tech Talk
August 5, 2009

ABSTRACT

Presented by Nate Lawson

Encrypting and decrypting, choosing a random number, signing and verifying -- it all seems so logical. But the road to hell is paved with good intentions and a copy of "Applied Cryptography".

This talk will cover recent crypto vulnerabilities in widely-deployed systems and how the smallest oversight resulted in catastrophe. You'll learn why public key crypto is like a Ford Pinto in a demolition derby, the meaning of "PBKDF2", and how Web 2.0 reinvented 1970's-style password hashing, badly. And maybe, just maybe, you'll leave with a newfound respect for the utter brittleness of even the simplest crypto.

Nate Lawson is the founder of Root Labs, which specializes in the design and analysis of embedded security and cryptography. Previously, he worked at Cryptography Research, analyzing cryptographic products and co-designing the Blu-ray content protection layer known as BD+.

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 6 dislikes

Link to this comment:

Share to:
see all

All Comments (7)

Sign In or Sign Up now to post a comment!
  • hvala

  • @janspambox It seems pretty higgh level to me, you already even selected the encryption algorithm... low level is more to the number theory part of things, like the mentioned PRNG function, or if you have to to meddle with primes and the like. Though you should also be careful on the key selection related stuff too, even if relatively high level, but since you seem to just be signing now, you are assuming you did everything right up to THAT point.

  • This is one of the guys responsible for me haveing to do a )(&*^%^ update on my Blu-Ray everytime I buy a new release :(

  • Does anyone know if System.Security.Cryptography.E­CDsaCng.SignData() (.NET crypto stuff, takes byte[] data and spits out byte[] signature) is to be considered high-level (good) or low-level (evil)?

  • the tee shirt is a secret message from nephillium L-5

  • Nope, but I see what you mean. It is just a logo on his shirt. Check it out @ 49:23.

  • Is the  logo or whatever it is on that guys T-Shirt censored @ 12:55 and following? Just wondering.

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more