Why Cybersecurity Depends on Strong Cryptography

352 views
•
April 6, 2018
by
RSAC Cybersecurity
YouTube video player
Why Cybersecurity Depends on Strong Cryptography

TL;DR

Cybersecurity depends on cryptography for confidentiality, data integrity, entity authentication, and data origin authentication. That foundation can weaken when organizations neglect key management, retain older algorithms and shorter keys for backward compatibility, use unauthorized keys or self-signed certificates, or rely on vulnerable cryptographic libraries. Cybersecurity must protect cryptographic systems while cryptography protects information and communications.

Transcript

Welcome to our session on Cyber is Hot, Crypto is Not, part of the RSA Conference two thousand eighteen. Cybersecurity is the big buzzword these days, having gone through many progressive names for our profession in the past, data security, computer security, information security. Now it's cybersecurity. And cybersecurity is the hot au courant term... Read More

Key Insights

  • Cryptography is the underlying framework that supports cybersecurity, even though cybersecurity receives more attention as the current term for protecting information and communication systems. Weak or ignored cryptography can therefore undermine the protections built above it.
  • Cybersecurity is the activity, process, ability, or capability used to protect information and communication systems, including their information, against damage, unauthorized use, modification, or exploitation by an actor.
  • Cryptography is the use of mathematical techniques to provide security services, including confidentiality, data integrity, entity authentication, and data origin authentication. These services form part of the technical foundation required by cybersecurity.
  • Cryptographic key management is a complete life cycle that includes generation, distribution, usage, backup, revocation, termination, and archiving. Each stage matters because poorly controlled keys can compromise otherwise sound cryptographic protections.
  • Cybersecurity and cryptography protect each other through a reciprocal relationship. Cryptography helps secure cybersecurity systems, while cybersecurity safeguards the cryptographic libraries, keys, processes, and supporting systems on which those protections depend.
  • Man-in-the-middle attacks can be examined through asymmetric encryption and asymmetric digital-signature exchanges between Alice and Bob. Flow diagrams can show how an attacker positioned between participants exploits weaknesses in the cryptographic foundation.
  • Cryptographic libraries can contain common vulnerabilities and exposures, whether they use open-source code or other well-known implementations. Reviewing these underlying libraries is necessary because their weaknesses can affect the cybersecurity services built upon them.
  • Backward compatibility can preserve older algorithms, shorter keys, and weaker protocols inside vendor products. Keeping these outdated options available for compatibility is described as a source of increasing problems for cryptographic and cybersecurity protections.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why does cybersecurity depend on cryptography?

Cybersecurity depends on cryptography because mathematical security techniques provide confidentiality, data integrity, entity authentication, and data origin authentication. The session describes cybersecurity as the visible tip of an iceberg and cryptography as the supporting framework underneath it. If that foundation becomes weak, ignored, or outdated, the cybersecurity protections built on top of it may also become unreliable.

Q: What is the difference between cybersecurity and cryptography?

Cybersecurity is the activity, process, ability, or capability through which information and communication systems, along with the information they contain, are protected against damage, unauthorized use, modification, or exploitation. Cryptography is more specific: it uses mathematical techniques to deliver security services such as confidentiality, integrity, entity authentication, and authentication of the data's origin.

Q: What stages are included in the cryptographic key life cycle?

The cryptographic key life cycle begins with key generation and continues through key distribution and usage. Key usage also includes considerations such as backup. Later stages include key revocation, key termination, and the archiving of keys. Every stage requires attention because failures in life-cycle management can lead to unauthorized keys and weaken the cryptographic foundation supporting cybersecurity.

Q: How do cybersecurity and cryptography protect each other?

Cryptography helps secure cybersecurity by providing foundational services such as confidentiality, integrity, and authentication. Cybersecurity also secures cryptography by protecting the systems, libraries, processes, and keys used to implement those services. This reciprocal relationship means that neglected cryptographic components can weaken cybersecurity, while inadequate cybersecurity controls can leave cryptographic assets and their management exposed.

Q: How can weak cryptography enable a man-in-the-middle attack?

A man-in-the-middle attack can occur when an attacker positions themselves between communicating parties, represented in the session by Alice and Bob, and exploits weaknesses in asymmetric encryption or asymmetric digital signatures. The planned discussion uses diagrams and flow diagrams to show the attack process and explain why the cryptographic foundation must be strengthened to protect communications.

Q: Why are cryptographic libraries important to cybersecurity?

Cryptographic libraries implement the underlying functions that cybersecurity products and services rely upon. The session plans to examine common vulnerabilities and exposures in libraries using open-source code as well as other well-known implementations. If a library is vulnerable, aging, or insufficiently maintained, the systems that depend on its cryptographic operations may inherit those weaknesses.

Q: Why can backward compatibility weaken cryptographic security?

Backward compatibility can weaken security because vendors may retain older algorithms, shorter keys, and weaker protocols inside their products so those products continue working with older systems. The session identifies this retention as a growing source of problems. Compatibility therefore needs to be considered alongside the strength and condition of the cryptographic mechanisms available within a product.

Q: What bad cryptographic practices should organizations recognize?

The session identifies several practices and conditions that deserve scrutiny, including unauthorized cryptographic keys, self-signed certificates, common vulnerabilities in security services, vulnerable cryptographic libraries, weak key management, older algorithms, shorter keys, and weaker protocols retained for backward compatibility. Recognizing these issues helps reveal when cybersecurity controls rest on a faulty or poorly maintained cryptographic foundation.

Summary & Key Takeaways

  • Cybersecurity protects information and communication systems against damage, unauthorized use, modification, and exploitation. Cryptography supports that mission with mathematical techniques that provide confidentiality, data integrity, entity authentication, and data origin authentication. Treating cryptography as merely supplemental can obscure weaknesses in the foundation on which broader cybersecurity capabilities depend.

  • Cryptographic security requires management across the complete key life cycle. The identified stages include key generation, distribution, usage, backup, revocation, termination, and archiving. Neglecting any of these stages can create problems such as unauthorized keys and weaken the cryptographic framework supporting information systems and broader cybersecurity protections.

  • The planned session examines practical weaknesses through asymmetric encryption, digital signatures, and an Alice-and-Bob man-in-the-middle scenario. It also reviews vulnerabilities in cryptographic libraries, including open-source and well-known implementations, plus products that preserve older algorithms, shorter keys, and weaker protocols to maintain backward compatibility, potentially causing increasing security problems.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚