Re: Access control for IoT
Tony Arcieri <[email protected]> Sat, 16 Jan 2016 10:26:17 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAHOTMV+_hStN7T5WqN1XzyA8Joo-7fRqDkbMcrAPZFKGkDMaBg@mail.gmail.com> |
--===============6933855516228539550== Content-Type: multipart/alternative; boundary=047d7bd756e801cff8052977a9fe --047d7bd756e801cff8052977a9fe Content-Type: text/plain; charset=UTF-8 On Sat, Jan 16, 2016 at 9:59 AM, Alan Karp <[email protected]> wrote: > I think one reason for lack of interoperability is the desire for lock-in > by the vendors. Another is lack of standards. > > As far as privacy versus functionality, I believe 99+% of people will > choose the latter without blinking an eye. > IoT is in a tough spot. Devices are constrained, so implementers often seek to cut corners on the systems they use in order to boost performance and/or reduce power usage. At the same time, these devices require lots of functionality out of the cryptosystems they use for secure operation and access control. These two constraints don't play well together, and the result is often quite broken. I was just at RealWorldCrypto where a speaker from Microsoft was talking about a transport encryption protocol designed for non-IP-based transports used by IoT devices. He threw up a slide with a protocol description and someone in the audience broke it on the spot (identity misbinding attack). SecureRF is pushing their "Algebraic Eraser" public key algorithm, which they claim has performance which scales linearly to the key size as opposed to quadratically like ECC or RSA: https://twitter.com/kennyog/status/688409890914717700 But it was already broken once, and apparently a new paper is coming out next week breaking their "fix". I have seen plenty of IoT frameworks from real cryptographers which look rather interesting, but these are all research projects which are half-baked and don't have a suitable implementation for use on real hardware. All that said, as far as I can tell there really isn't anything to recommend so far that remotely resembles a real option in this space. The best I can recommend are half-baked research projects. -- Tony Arcieri --047d7bd756e801cff8052977a9fe Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">On S= at, Jan 16, 2016 at 9:59 AM, Alan Karp <span dir=3D"ltr"><<a href=3D"mai= lto:[email protected]" target=3D"_blank">[email protected]</a>></spa= n> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px = 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-= style:solid;padding-left:1ex"><div dir=3D"ltr">I think one reason for lack = of interoperability is the desire for lock-in by the vendors.=C2=A0 Another= is lack of standards.<div><br></div><div>As far as privacy versus function= ality, I believe 99+% of people will choose the latter without blinking an = eye.</div></div></blockquote><div><br></div><div>IoT is in a tough spot. De= vices are constrained, so implementers often seek to cut corners on the sys= tems they use in order to boost performance and/or reduce power usage.</div= ><div><br></div><div>At the same time, these devices require lots of functi= onality out of the cryptosystems they use for secure operation and access c= ontrol.</div><div><br></div><div>These two constraints don't play well = together, and the result is often quite broken.</div><div><br></div><div>I = was just at RealWorldCrypto where a speaker from Microsoft was talking abou= t a transport encryption protocol designed for non-IP-based transports used= by IoT devices. He threw up a slide with a protocol description and someon= e in the audience broke it on the spot (identity misbinding attack).</div><= div><br></div><div>SecureRF is pushing their "Algebraic Eraser" p= ublic key algorithm, which they claim has performance which scales linearly= to the key size as opposed to quadratically like ECC or RSA:</div><div><br= ></div><div><a href=3D"https://twitter.com/kennyog/status/68840989091471770= 0">https://twitter.com/kennyog/status/688409890914717700</a><br></div><div>= <br></div><div>But it was already broken once, and apparently a new paper i= s coming out next week breaking their "fix".</div><div><br></div>= <div>I have seen plenty of IoT frameworks from real cryptographers which lo= ok rather interesting, but these are all research projects which are half-b= aked and don't have a suitable implementation for use on real hardware.= </div><div><br></div><div>All that said, as far as I can tell there really = isn't anything to recommend so far that remotely resembles a real optio= n in this space. The best I can recommend are half-baked research projects.= </div><div><br></div></div>-- <br><div class=3D"gmail_signature">Tony Arcie= ri<br></div> </div></div> --047d7bd756e801cff8052977a9fe-- --===============6933855516228539550== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============6933855516228539550==--