210 likes | 328 Views
I crypt, You crypt. Budi Rahardjo Institut Teknologi Bandung br@paume.itb.ac.id – http://budi.insan.co.id Invited Talk at Indonesian Cryptology and Information Security Conference Jakarta, 30-31 March 2005. Gur Pelcg Fbat. V pelcg, lbh pelcg Jr nyy pelcg, sbe V pelcg Yn, yn, yn ….
E N D
I crypt, You crypt Budi Rahardjo Institut Teknologi Bandung br@paume.itb.ac.id – http://budi.insan.co.id Invited Talk atIndonesian Cryptology and Information Security Conference Jakarta, 30-31 March 2005
Gur Pelcg Fbat V pelcg, lbh pelcg Jr nyy pelcg, sbe V pelcg Yn, yn, yn … Budi Rahardjo - I crypt, you crypt
ROT13 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z n o p q r s t u v w x y z a b c d e f g h i j k l m • Characters are shifted 13 places • Commonly used during the Usenet newsgroup era to post puzzles or offensive messages • There are many tools to perform rot13 • Usenet news readers • Text editors: vi, emacs • Now, web-based: http://www.rot13.com Budi Rahardjo - I crypt, you crypt
The Crypt Song I crypt, you crypt We all crypt, for I crypt La, la, la … Adapted from “The I scream ice cream” song I scream, you scream We all scream for ice cream La, la, la Monday, Tuesday We all scream for sundae La, la, la Budi Rahardjo - I crypt, you crypt
Daily-crypto-live • Cryptography is part of our (digital?) live • GSM communication (with A5) • Bank ATM (PIN, encrypted communication) • Microsoft Office files can be saved with password (RC4) • Access control (password, token, smartcard) • SSL in e-commerce • If that’s not enough, roll your own coding scheme for puzzles, quizzes, … secret SMS messages ! • Many more … • What does it mean? Budi Rahardjo - I crypt, you crypt
http://www.randomhouse.com/doubleday/davinci/ Budi Rahardjo - I crypt, you crypt
A5 @ GSM Source: http://www.issadvisor.com/columns/GSMSecurity/GSMSecurity.htm Budi Rahardjo - I crypt, you crypt
Microsoft Office Password Budi Rahardjo - I crypt, you crypt
What does it mean? • It means that we already dependent on crypto for • Commercial environment • Government • Military • and … personal (home) Budi Rahardjo - I crypt, you crypt
Impact To Government • Should the government come up with regulation? • Over protected/regulated • Privacy on the line • Bad for business • Under protected • False sense of security • National security issues? • How to strike balance? • There will be more debates in the future Budi Rahardjo - I crypt, you crypt
Crypto problems in Indonesia • The problems • Lack of understanding crypto. A difficult subject. Not much interest. Don’t care… • Lack of expertise in Indonesia(?) • How to build and keep talented human resources in Indonesia? • That is why we need theSociety ofIndonesianCryptology and InformationSecurity Budi Rahardjo - I crypt, you crypt
Resulting in … • As a result • Technology dependencies are high • We are at the mercy of vendors and other governments • We were given a sub-standard products • (e.g. shorter key length, which results in less secure system) Budi Rahardjo - I crypt, you crypt
International Surveilance Source: IEEE Spectrum April 2003 Budi Rahardjo - I crypt, you crypt
Listen, Filter, Store Source: IEEE Spectrum April 2003 Budi Rahardjo - I crypt, you crypt
Road from Crypto to Security • Some would think that encryption can solve all security problems. Wrong! • Crypto alone cannot solve all security problems • e.g. availability problems • All of this lead to information security Budi Rahardjo - I crypt, you crypt
Initiatives • There has to be security initiative(s) to solve this problem, by • Research • Product development • Applications • Standards (for military, commercial, and personal/home use) • Certification • Education [crypto for kids?] • Indonesia’s National Strategy to Secure Cyberspace Budi Rahardjo - I crypt, you crypt
Security Initiative Drivers • Who is the driver? • Government • Academia • Commercial entities • Special interest groups(such as our society?) Budi Rahardjo - I crypt, you crypt
What to do next? Let’s hope that this is conference continues (annually?) Let’s discuss this in this forum … Budi Rahardjo - I crypt, you crypt
Thank You Gunax Lbh Budi Rahardjo - I crypt, you crypt