Art of Information Security

Random Insights on Protecting Data, Privacy, and Digital Infrastructure
  • rss
  • Home
  • About
  • Contact

Last HOPE Session Videos - Seeded by AoIS

To be honest, 2600’s The Last HOPE conference didn’t really catch my attention at first. But some of the sessions, especially  ”Crippling Crypto: The Debian OpenSSL Debacle”. That presentation, by Jacob Appelbaum, Dino Dai Zovi, Karsten Nohl is a winner. Not only do they provide a fantastic and detailed description of how OpenSSL’s random number generator was accidentally lobotomized, they also demonstrate how to leverage cheap cloud computing to generate the set of bad keys that resulted. (All of them!) 

At any rate, legit torrents of the video presentations are available from The Last HOPE Video Tracker. Art of Information Security is seeding torrents, and plans to do so for the next 10 days.

Check ‘em out.

Cheers, Erik

Comments
No Comments »
Categories
Cryptography, News and Info
Tags
Cryptography, Entropy, openSSL, Random Numbers, The LAST Hope
Comments rss Comments rss
Trackback Trackback

What do you want to know about Cryptography in the Enterprise ?

I am working on a presentation entitled “Lessons Learned Deploying and Managing Enterprise Cryptosystems“. I will be presenting this at Information Security World 2008. In the 45 minutes I have for the presentation, it is my goal to touch on several key lessons learned in my work with cryptographic controls over the past several years. Cryptosystems is a broad topic, and can include not only techniques (encryption, digital signatures, timestamps), but also key management and implementation issues. There is a lot of material that I have available to draw from, and I want to make sure that the presentation includes the most valuable and relevant points that it can. After giving a presentation, there is almost nothing more disappointing than reviewing the feedback forms only to find out what people really wanted to know. This is especially disappointing if it is material you could have easily included…

I would love to know what kinds of questions you have and would like to see addressed.

In addition to your question, please provide a little context, such as:

- What are the drivers for your use of cryptographic controls (data protection, compliance, etc.)?
- Will your deployment be externally audited?

Cheers,
Erik

Cross posted on Linked In.

Comments
1 Comment »
Categories
Cryptography, News and Info
Tags
Audit Preparation, Cryptography, Key Management
Comments rss Comments rss
Trackback Trackback

/erik/random



The Podcast...

iTunes Link

Currently Reading...


Alan may be my new favorite business book author.



This is the total guide - why "awareness", how to justify "awareness", how to plan, make it happen, and measure the results.

Categories

  • Analysis and Insight
  • Cryptography
  • Identity Management
  • News and Info
  • Podcast
  • Professional Development
  • Security Faux Pas
  • Site Info

Blogroll

  • (ISC)2
  • Got Entropy ?
  • GTAG white papers
  • NIST Info Sec Resource Center
  • The Photographer’s Right Page


Creative Commons License
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox