Rory · @rory
330 followers · 950 posts · Server infosec.exchange

Cryptography gadget of the day: Javascript Object Signing and Encryption (JOSE) datatracker.ietf.org/wg/jose/d and the jose command line utility (h/t Nathan McCallum)

I appreciate this little set of (draft) standards because they codify quite a bit of best practice. The input and output formats (JSON or condensed base64url) are highly portable, and even printable, resulting in good crypto agility. The algorithm selections are limited to reasonable, recommended combinations, key sizes and padding. Proper key wrapping or key encryption is automatic and relatively effortless.

jose is such a better choice for the uninitiated than openssl and the vast troves of crap advice on Stackoverflow. It's also a decent learning tool. If there's any question about the algorithm in use, the JWA RFC7518 describes the details and operation of each in a manner more readable than most RFCs.

Looking for a tool to encrypt log files before shipping them off to NFS or S3 storage? How about creating a signed message? jose is probably going to be easier than openssl. Heck, openssl doesn't even do AEAD on the CLI anymore.

#cryptography #cli #tooloftheday #portability #cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
475 followers · 1263 posts · Server fosstodon.org

Maybe will change this from "HARD" to "NOT SO HARD" or even "EASY". 🤷‍♂️

No no, don't worry. Not today, not tomorrow. But like MD5 was "unbreakable" long time ago, technical advances are coming fast.

Source xkcd.com/936/

#quantumcomputing #xkcd #quantumsecurity #security #cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
467 followers · 1236 posts · Server fosstodon.org

I am afraid that if current encryption schemes are broken by it will more like being hit by a deadly meteroit then an earthquake. ☄️ This will not leave any technological component untouched.

"Quantum computing looms in our future like a technological earthquake, because quantum decryption threatens to compromise a foundational element of data encryption schemes."

mondaq.com/unitedstates/fin-te

#quantumcomputing #pqc #postquantum #cryptograhpy #cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
461 followers · 1215 posts · Server fosstodon.org

"Even if the Schnorr-based technique won’t break the Internet, quantum computers could eventually do so by running Shor’s algorithm. Security researchers have been busy developing a number of alternative cryptographic systems that are seen as less likely to succumb to a quantum attack, called post-quantum or quantum-safe. "

Are quantum computers about to break online privacy?
nature.com/articles/d41586-023

#security #quantumcomputing #pqc #postquantumcryptography #cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
356 followers · 991 posts · Server fosstodon.org

Since it is often believed that replacing crypto is easy, shows here that it isn't. There are from now on 8 years for fixing software and hardware using sha-1. Maybe as a reminder for those who still believe that this is an easy job.

“Modules that still use SHA-1 after 2030 will not be permitted for purchase by the federal government,” Celi said.

nist.gov/news-events/news/2022

#nist #cryptography #cryptoagility #quantumcomputing

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
323 followers · 775 posts · Server fosstodon.org

@WinstonSmith @tc Hopefully the companies are re-encrypting as well. I guess this is the big issue with companies: this won't happen fast if there is not some kind of -- lets call it -- setup. And the appropriate to support this.

If not, it can talk years before an alternative storage encryption is setup up. I have seen this where a replacement of a DMS took almost 5 years. 😱

#cryptoagility #architecture

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
249 followers · 623 posts · Server fosstodon.org

The threat: , the solution: by National Institute of Standards and Technology (NIST).

"In 2019, a team of researchers factored a 795-bit RSA key, making it the biggest key size ever to be solved." and "The researchers estimated that the sum of the computation time for both of the new records was about 4,000 core-years using Intel Xeon Gold 6130 CPUs (running at 2.1 GHz)."

arstechnica.com/information-te

#quantumcomputer #pqc #cryptoagility #cryptography

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
225 followers · 556 posts · Server fosstodon.org

Still some way to go but it is time to start to experiment with new algorithms and to get the hands dirty with . Expertise in won't come over night. Changing systems will take years.

"Governments need to invest in cybersecurity that can defend against the future threat of bad actors using quantum computers that are exponentially faster than ordinary machines, a cryptography expert said."

bworldonline.com/sparkup/2022/

#pqc #cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
225 followers · 556 posts · Server fosstodon.org

"a strategy for the migration of information technology systems of the Federal Government to post-quantum cryptography is needed" ==> 👍

#cryptoagility

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
225 followers · 556 posts · Server fosstodon.org

“All we need to do is replace those algorithms with newer versions that are quantum-resistant,” said Marc Witteman , CEO of Riscure. “Unfortunately, that is easier said than done.”

Michael Osborne, CTO of IBM Quantum Safe, said during a recent webinar, “We understand quantum-safe as being safe in the quantum era. Part of that is replacing the cryptography that we use."

Less talk, more action + 💯

semiengineering.com/post-quant

#cryptoagility #qkd #cryptography #quantumtechnology #quantumcomputing

Last updated 3 years ago

Gottfried Szing :unverified: · @kjoo
225 followers · 556 posts · Server fosstodon.org

@roomey I am neither an expert in this area, but I haven't seen a suggestion to move to one of the possible candidates of the competition.

Why? Because they are still not the final candidates and as it was demonstrated in August with the SIKE, you can see, how quickly a possible winner can be cracked. I would really defer the move to one of the candidates.

But yes, is a must nowadays. Not only because of . It is generally needed!

#nist #cryptoagility #quantumcomputing

Last updated 3 years ago

exfil · @exfil
2 followers · 8 posts · Server noc.social