FYI: Dan's talk on 27c3 in Berlin

Erwin Hoffmann <[email protected]> Sat, 12 Feb 2011 19:07:09 +0100
Newsgroups gmane.mail.qmail.general,gmane.network.djbdns
Organization FEHCom
Message-ID <[email protected]>
--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi together,

for those, who are interested:=20

DJB gave a talk on 27c3 'Hacker congress' (at December 28th, 2010) in Berli=
n:

"High-speed high-security cryptography encrypting and authenticating the wh=
ole internet"

In essence, Dan

- critices DNSSec from first principles ('CIA') and explaining possible amp=
lification attacks, and addressing the problem of static signing keys,

- introduces briefly DNSSec with ECC and NYM deployed Public Keys,

- outlines CurveCP, a new protocol, using UDP services while encrypting the=
 payload (asymmetrically) by means of ECC. This could be used for general H=
TTP traffic (instead using standard TCP).

--

What is interesting, challenging, and extraordinary is the approach - unlik=
e TLS - to directly encrypt data with ECC and not to first negotiate a shar=
ed secret for (later) symmetrical en/de-cryption. Dan tries to convince the=
 public that asymmetric cryptography by ECC is not heavy burdon on today's =
CPUs.

Sources:

His talk: http://cr.yp.to/talks/2010.12.28/slides.pdf

His life presentation: http://vimeo.com/18279777

--

Interesting enough, apart from Dan's approach, Google also tries to tie dow=
n the latency introduced by TLS (for instant HTTP traffic):

http://tools.ietf.org/html/draft-agl-tls-snapstart-00

--

Thus, given the current hardware capabilities, not the CPU load is problema=
tic for encryption, but rather the (slow) current approach, to at first set=
 up a security context/session and negotiate on a cipher.


Enjoy!

regards.
--eh.

PS: Sorry for potentially receive this mail twice. It is worth it!

--=20
Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de

--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk1WzE0ACgkQzAMRjn5ANL5XMACfYYiu02VsBFfsAUtv3TabO4Tj
gK4AnA204EZUiRtkPFxMeNTlRNllzDRH
=GmMi
-----END PGP SIGNATURE-----

--Signature=_Sat__12_Feb_2011_19_07_09_+0100_Kzcjbm1hqksq5BtX--