• On The Insider: Britney's Bikini-Clad Top 10
April 8, 2008 3:02 PM PDT

Cryptographers speak of threats, voting, and Blu-Ray rumors

by Robert Vamosi

On Tuesday, the creators of the Diffie-Hellman key exchange, a cryptographic protocol, and two of the creators of EMC security division RSA gathered onstage for the annual cryptographers' panel at RSA 2008 in San Francisco.

First, panel members offered their perspectives on the state of security since last year, then they answered questions posed by a moderator. The panel included: Whitfield Diffie, chief security officer at Sun Microsystems; Martin Hellman, professor emeritus of electrical engineering at Stanford University; Ronald Rivest, professor of electrical engineering and computer science at MIT; and Adi Shamir, professor of computer science at the Weizmann Institute of Science in Israel. The moderator was by Burt Kaliski, founding scientist at RSA Laboratories.

Diffie began the discussion, saying that after 80 years, "we've gotten cryptography to a fairly good point," but added that "the Internet's a mess." He said that on the Internet, "defense--pure defense--simply doesn't work." He said that where it takes us months and years to secure something, it takes the opponent only hours. "They can run rings around us." He then mentioned that some in the government are starting to talk about going to where the opponents live and using a variety of means to shut them down.

Hellman showed a photograph of a glider flying over a runway. Himself a pilot, he said the greatest risk was executing a maneuver that most people consider 99.9 percent safe. Hellman said that "humans are not good in judging low-probability events," and cautioned against complacency. He said he hoped that the non-security world would reach a tipping point and start taking security seriously. (Malcolm Gladwell, author of The Tipping Point, is an RSA keynote speaker on Thursday.)

Rivest briefly mentioned Alan Turing, to whom this year's RSA conference is dedicated. Turing is best known for the Turing Test, a process that determines a machine's ability to demonstrate intelligence. What Rivest really wanted to talk about, however, was electronic voting. He said cryptography is relevant to creating end-to-end security. He's part of a group that has released a public proposal on voting system standards. One of the key parts is the definition of "dependent" and "independent" software on a voting system. He said software dependent is a category where a bug or a flaw could easily change the end result; this is along the lines of work done recently by Professor Ed Felten and his grad students at Princeton. Software independent is where the system doesn't entirely depend on the software and uses paper or some other means of capturing the vote. He favors voting systems that are software independent.

Shamir gave a short recitation of hacks within the last year or so on various cryptographic systems, mentioning in particular recent attacks on various municipal transit systems, such as Boston's Charlie Card and London's Oyster Card. Most curious, however, were his final comments about the adoption of Blu-Ray DVD discs by Warner Bros. He said he'd wondered about the tipping point in the Blu-Ray vs. HD DVD battle, and said he'd heard a rumor--and stressed it was only a rumor--that Blu-Ray had better security overall than HD DVD. If true, he said, security is finally starting to become a factor in consumer electronics.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
Ahh.... NO!
by MyRightEye April 8, 2008 3:56 PM PDT
"If true, he said security was finally starting to become a factor in
consumer electronics."


Ahh.... NO!

So consumers chose a more limiting choice because they are
concerned about piracy?

And you have the gaul to publish your own writing. Funny.
Reply to this comment
No, no, no
by gsmiller88 April 8, 2008 5:44 PM PDT
Consumers didn't choose Blu-ray.....The movie studios chose it for
them after they were paid off by Sony!
complacency
by cyberDJ-2038765336053745013836 April 8, 2008 5:55 PM PDT
As long a people believe their computers are "more secure" than others [we all know who and what I'm referring to], malware will continue to infect and affect everyone.

The human idiot at the keyboard is the reason viruses spread and identities are stolen; not an OS vulnerability.
Reply to this comment
Not always nt
by The_Decider April 10, 2008 8:31 PM PDT
nt
(4 Comments)
  • prev
  • 1
  • next

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right