FYI: Dan's talk on 27c3 in Berlin
Erwin Hoffmann <[email protected]> Sat, 12 Feb 2011 19:07:09 +0100
| Newsgroups | gmane.mail.qmail.general,gmane.network.djbdns |
|---|---|
| Organization | FEHCom |
| Message-ID | <[email protected]> |
--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Hi together,
for those, who are interested:=20
DJB gave a talk on 27c3 'Hacker congress' (at December 28th, 2010) in Berli=
n:
"High-speed high-security cryptography encrypting and authenticating the wh=
ole internet"
In essence, Dan
- critices DNSSec from first principles ('CIA') and explaining possible amp=
lification attacks, and addressing the problem of static signing keys,
- introduces briefly DNSSec with ECC and NYM deployed Public Keys,
- outlines CurveCP, a new protocol, using UDP services while encrypting the=
payload (asymmetrically) by means of ECC. This could be used for general H=
TTP traffic (instead using standard TCP).
--
What is interesting, challenging, and extraordinary is the approach - unlik=
e TLS - to directly encrypt data with ECC and not to first negotiate a shar=
ed secret for (later) symmetrical en/de-cryption. Dan tries to convince the=
public that asymmetric cryptography by ECC is not heavy burdon on today's =
CPUs.
Sources:
His talk: http://cr.yp.to/talks/2010.12.28/slides.pdf
His life presentation: http://vimeo.com/18279777
--
Interesting enough, apart from Dan's approach, Google also tries to tie dow=
n the latency introduced by TLS (for instant HTTP traffic):
http://tools.ietf.org/html/draft-agl-tls-snapstart-00
--
Thus, given the current hardware capabilities, not the CPU load is problema=
tic for encryption, but rather the (slow) current approach, to at first set=
up a security context/session and negotiate on a cipher.
Enjoy!
regards.
--eh.
PS: Sorry for potentially receive this mail twice. It is worth it!
--=20
Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de
--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAk1WzE0ACgkQzAMRjn5ANL5XMACfYYiu02VsBFfsAUtv3TabO4Tj
gK4AnA204EZUiRtkPFxMeNTlRNllzDRH
=GmMi
-----END PGP SIGNATURE-----
--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX--