14
Cybercalypse, HeartBleed : Is our Government Listening Ajit [email protected]

Cybercalypse , HeartBleed : Is our Government Listening

  • Upload
    errol

  • View
    41

  • Download
    0

Embed Size (px)

DESCRIPTION

Cybercalypse , HeartBleed : Is our Government Listening. Ajit [email protected]. Stories. The Backbone The Nexus A Random Story The Curves You Like My Heart is Bleeding History Repeats it self… Conclusion Is our Government Listening. Dedicated to…. The BackBone. - PowerPoint PPT Presentation

Citation preview

Page 1: Cybercalypse ,  HeartBleed  : Is our Government Listening

Cybercalypse, HeartBleed : Is our Government Listening

[email protected]

Page 2: Cybercalypse ,  HeartBleed  : Is our Government Listening

Stories

• The Backbone• The Nexus• A Random Story• The Curves You Like• My Heart is Bleeding• History Repeats it self…

ConclusionIs our Government Listening

Page 3: Cybercalypse ,  HeartBleed  : Is our Government Listening

Dedicated to…

Page 4: Cybercalypse ,  HeartBleed  : Is our Government Listening

The BackBone

OpenSSL – Defacto Standard for all the cryptography Library.

Free, Open, Well Maintained by Community

*Hundreds of Contributors*

Page 5: Cybercalypse ,  HeartBleed  : Is our Government Listening

The Nexus

Openssl FIPS Moduleopenssl-1.0.1i.tar.gz openssl-fips-2.0.7.tar.gz

FIPS ComplianceNeeds NIST/NSA approved third party

“fipscansiter”

Page 6: Cybercalypse ,  HeartBleed  : Is our Government Listening

The Nexus

Page 7: Cybercalypse ,  HeartBleed  : Is our Government Listening

A Random Story

Told By :• Microsoft cryptologists - Dan Shumow & Niels

Ferguson• Edward Snowden• Bruce Schneier • @Cocon• IS That Clear

Page 8: Cybercalypse ,  HeartBleed  : Is our Government Listening

The Curves You Like

The Story• RSA Sucks, not for Phones• Elliptical Curve Crypto• Patient owned by RIM• Patient bought by NSA• Made Public• Now We all Can use it

Page 9: Cybercalypse ,  HeartBleed  : Is our Government Listening

Issues with Curves

• NISTP -- 256�• Coefficients generated by hashing the

unexplained seed • C49d3608, 86e70493, 6a6678e1, 139d26b7,

819f7e90• It is possible to define some arbitrary

parameters.• Web browsers will only support a handful of

predefined curves, usually NIST P-256, P-384 and P-521.

Page 10: Cybercalypse ,  HeartBleed  : Is our Government Listening

My Heart is Bleeding

• SSL Handshake Protocol• Very Costly, CPU intensive• Optimization– Session ID cashing– Keep Alive Session

• HeartBeat ModuleRobin SeggelmannDr. Robin Seggelmann

Page 11: Cybercalypse ,  HeartBleed  : Is our Government Listening

History

• Remember SE-Linux?• Capture of communicaitons of David Headley

& Tahawwur Rana

• Acquisition of Skype• Acquisition of Whatsapp

Page 12: Cybercalypse ,  HeartBleed  : Is our Government Listening

Conclusion

Page 13: Cybercalypse ,  HeartBleed  : Is our Government Listening

Questions?

• Why doesn’t our government CONTRIBUTE– To clean & Use the OpenSSL

• Contribute to Open source pain points• Why doesn’t our government LISTEN– To other Govt.

• It’s an Asymmetric war– Why don’t we try n Get UNFair Advantage?

Page 14: Cybercalypse ,  HeartBleed  : Is our Government Listening

THANK YOU

• IS IT CLEAR?????• IF NOT, PLS talk to my Friend – Gurudev…