preview

5 Ways to Measure the Quality of Your Cryptography Essay

Good Essays

5 Ways to Measure the Quality of Your Crypto Introduction Cryptography is definitely become a more mainstream topic today. Almost every device in this world is connected to the internet and sharing information. At the same time of the increasing of number in the device, the number of sensitive data in the information shared between devices, application, and server is also increasing in a larger scale. That information must be protected, so that the sensitive data will remain private. The dominance attack today is not just about Denial of Services or Viruses just like 10 or 15 years ago. The nowadays attack is becoming more a specific purpose like data theft, eavesdropping, getting access to sensitive data like credit card numbers, …show more content…

Let’s think about the private key in the asymmetric infrastructure, if a private root key is stolen, then the trustworthy of the entire document issued by that root is undermined. And most of the time, it will need reissuing of all digital credentials that is part of the infrastructure. So that will be a time consuming process, and also at the same time, all the system that rely on those credentials is inoperable while the issuing process is taking place. There is no better reason of a poor implementation quality than heartbleed vulnerability. The first important thing here is that this is not a flaw on the SSL protocol itself, but it was a flaw in the OpenSSL implementation of the protocol. Specifically it is a flaw in the heartbeat extension which keeps the session alive between a client and server. So the door was widely open for attacker to crafts heartbeat request with short “payload” that requests a mismatched sized amount of data (memory) in return. The memory can contain sensitive data, passwords, keys, etc. Once the key has compromised, the attacker has the access to all of the traffic. The attacker will still have the access until the software is patched, or the keys in SSL certificates are updated. Many people already did the good thing in patching the OpenSSL, replacing SSL certificate, and revoking the old certificate. But they made a critical mistake of reusing the same

Get Access