April 8, 2008 3:02 PM PDT

Cryptographers speak of threats, voting, and Blu-Ray rumors

On Tuesday, the creators of the Diffie-Hellman key exchange, a cryptographic protocol, and two of the creators of EMC security division RSA gathered onstage for the annual cryptographers' panel at RSA 2008 in San Francisco.

First, panel members offered their perspectives on the state of security since last year, then they answered questions posed by a moderator. The panel included: Whitfield Diffie, chief security officer at Sun Microsystems; Martin Hellman, professor emeritus of electrical engineering at Stanford University; Ronald Rivest, professor of electrical engineering and computer science at MIT; and Adi Shamir, professor of computer science at the Weizmann Institute of Science in Israel. The moderator was by Burt Kaliski, founding scientist at RSA Laboratories.

Diffie began the discussion, saying that after 80 years, "we've gotten cryptography to a fairly good point," but added that "the Internet's a mess." He said that on the Internet, "defense--pure defense--simply doesn't work." He said that where it takes us months and years to secure something, it takes the opponent only hours. "They can run rings around us." He then mentioned that some in the government are starting to talk about going to where the opponents live and using a variety of means to shut them down.

Hellman showed a photograph of a glider flying over a runway. Himself a pilot, he said the greatest risk was executing a maneuver that most people consider 99.9 percent safe. Hellman said that "humans are not good in judging low-probability events," and cautioned against complacency. He said he hoped that the non-security world would reach a tipping point and start taking security seriously. (Malcolm Gladwell, author of The Tipping Point, is an RSA keynote speaker on Thursday.)

Rivest briefly mentioned Alan Turing, to whom this year's RSA conference is dedicated. Turing is best known for the Turing Test, a process that determines a machine's ability to demonstrate intelligence. What Rivest really wanted to talk about, however, was electronic voting. He said cryptography is relevant to creating end-to-end security. He's part of a group that has released a public proposal on voting system standards. One of the key parts is the definition of "dependent" and "independent" software on a voting system. He said software dependent is a category where a bug or a flaw could easily change the end result; this is along the lines of work done recently by Professor Ed Felten and his grad students at Princeton. Software independent is where the system doesn't entirely depend on the software and uses paper or some other means of capturing the vote. He favors voting systems that are software independent.

Shamir gave a short recitation of hacks within the last year or so on various cryptographic systems, mentioning in particular recent attacks on various municipal transit systems, such as Boston's Charlie Card and London's Oyster Card. Most curious, however, were his final comments about the adoption of Blu-Ray DVD discs by Warner Bros. He said he'd wondered about the tipping point in the Blu-Ray vs. HD DVD battle, and said he'd heard a rumor--and stressed it was only a rumor--that Blu-Ray had better security overall than HD DVD. If true, he said, security is finally starting to become a factor in consumer electronics.

Recent posts from Defense in Depth
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Column: Finally, ID fraud protection that works
Column: Will you be ditching your antivirus app anytime soon?
A real simple answer to password protection
Add a Comment (Log in or register) 4 comments
Ahh.... NO!
by MyRightEye April 8, 2008 3:56 PM PDT
"If true, he said security was finally starting to become a factor in
consumer electronics."


Ahh.... NO!

So consumers chose a more limiting choice because they are
concerned about piracy?

And you have the gaul to publish your own writing. Funny.
Reply to this comment View reply
complacency
by cyberDJ April 8, 2008 5:55 PM PDT
As long a people believe their computers are "more secure" than others [we all know who and what I'm referring to], malware will continue to infect and affect everyone.

The human idiot at the keyboard is the reason viruses spread and identities are stolen; not an OS vulnerability.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.