1import{B as l,Dt as a,Ot as r,R as s,U as d,a as Be,c as Ge,ct as Oe,lt as o,st as n}from"../chunks/DyEG9IH5.js";import"../chunks/DwdwGuwu.js";import"../chunks/XPhOh-Be.js";import{t as N}from"../chunks/BF0KUsjh2.js";import{t as i}from"../chunks/CKq3EId7.js";import{t as Re}from"../chunks/B-CG_ua0.js";var J={title:"Highlights From Real World Crypto 2020",description:'Things that made us go, "hmmmmmm"',author:"Patrick Walsh",date:"2020-01-17T18:34:53.323Z",image:"/images/blog/rwc-2020-hero.jpg",socialImage:"/images/blog/rwc-2020-social.jpg",categories:["technology"],keywords:[],canonical:"https://blog.ironcorelabs.com/highlights-from-real-world-crypto-2020-91f4d8b01915"},{title:ct,description:pt,author:ut,date:mt,image:ft,socialImage:gt,categories:yt,keywords:vt,canonical:wt}=J,je=l('<span class="icon icon-link"></span>'),Ee=l('<span class="icon icon-link"></span>'),Le=l('<span class="icon icon-link"></span>'),qe=l('<span class="icon icon-link"></span>'),ze=l('<span class="icon icon-link"></span>'),We=l('<span class="icon icon-link"></span>'),Fe=l('<span class="icon icon-link"></span>'),Ne=l('<span class="icon icon-link"></span>'),He=l('<span class="icon icon-link"></span>'),Ue=l('<span class="icon icon-link"></span>'),De=l('<span class="icon icon-link"></span>'),Qe=l('<span class="icon icon-link"></span>'),Je=l('<span class="icon icon-link"></span>'),Ke=l('<span class="icon icon-link"></span>'),Ve=l('<span class="icon icon-link"></span>'),Xe=l('<span class="icon icon-link"></span>'),Ye=l('<span class="icon icon-link"></span>'),Ze=l('<span class="icon icon-link"></span>'),et=l('<span class="icon icon-link"></span>'),tt=l('<span class="icon icon-link"></span>'),at=l('<span class="icon icon-link"></span>'),ot=l('<p>If youâre interested in how research around privacy and security is turning into real-world solutions, this is the best conference of the year. Each time I attend, I come away inspired by the work thatâs being done to make our digital world better.</p> <p>There were around 650 attendees this year with a 50/50 split between academic cryptographers on one side and engineers and researchers from industry on the other. The focus of the conference is on real-world applications of cryptography, real-world attacks, and real-world problems from policy to maturity of developer tools.</p> <h3 id="on-things-that-arebroken"><!>On Things That Are Broken</h3> <h4 id="tls-12-andbelow"><!>TLS 1.2 and Below</h4> <p>TLS 1.3 has been out and used in the wild in draft form since 2016. The final version was put out in August 2018. TLS 1.3 is faster and more secure than previous versions and so far, adoption is relatively low, <!> than TLS 1.2. Around 15% of the Alexa top 1 million websites have support for 1.3 and around 5% of all websites do.</p> <p>In addition to adoption statistics, we were treated to a presentation showing <!> and more specifically, problems with RSA Key Exchange and padding. Although TLS 1.3 doesnât support RSA Key Exchange (good!), the researchers were able to perform downgrade attacks on connections so that clients fell back to a vulnerable TLS version. Two steps forward, one step back.</p> <h4 id="sha-1"><!>SHA-1</h4> <p>SHA-1 was shown to be insecure back in 2005 (it had a good ten years before that), but it continues to enjoy widespread use in places like git and gpg. Researchers presented <!> showing how practical it has become (for around $45k in computing time) to produce a chosen-prefix collision. As an example, they constructed a GPG key that had the same signature as an existing GPG key.</p> <h4 id="ocb2"><!>OCB2</h4> <p>OCB2 was thought to be secure for 14 years and was included in at least one ISO standard. Then, in 2018, a paper pointing out a possible flaw in the security proof spurred a series of attacks and papersâââ8 in three monthsâââstarting with a forgery attack and culminating in a <!>. The story here is less about the flaws of OCB2, which is built on sound principles and shouldnât taint OCB1 or OCB3, and more about the scent of blood in the water that caused a number of research teams around the world to race to break the algorithm.</p> <p><!> A cryptanalytic frenzy on OCB2</p> <h4 id="unnamed-hardware-security-modulevendor"><!>Unnamed Hardware Security Module Vendor</h4> <p>Some âmajor HSM companyâ that protects the secrets of large organizations and Western Governments has been pwned every which way. The company is unnamed but there are only two major HSM vendors left in the world and only one of them released patches around when this research came out.</p> <p>In short, they apparently spend all of their 3rd-party audit money testing how well the hardware protects secrets from hardware attacks, but standards like FIPS 140â2 donât require them to test the softw
1are of their systems.</p> <p>After these <!> they could remotely break in, extract all secrets, and replace the firmware with their own, I bet this will change.</p> <h4 id="the-encryption-wars"><!>The Encryption Wars</h4> <p>Every administration since President Clinton has attacked strong encryption, unfortunately, but Jennifer Granick of the ACLU reminded us that âthe Governmentâ is not one unified entity waging war here. The State Department wants tools that protect human rights, the FTC wants to protect privacy, and parts of the Department of Homeland Security such as the CyberSecurity division believe strong encryption is needed for our security as a nation.</p> <p>Unfortunately, Attorney General Barr has turned encryption into a signature issue and this time theyâre moving beyond the terrorism argument and pushing the child-abuse argument instead. Nevermind, as Jennifer points out, that there are measures and money for this problem that are sitting on the sidelines right now.</p> <p>Jennifer also made the point that a focus from the community on encryption alone is myopic. We should be worried about metadata collection, warrantless access to commercial data, collected data retention times, law enforcement hacking, and a host of other issues.</p> <p>This talk had a number of great points and included reasonable discussion of trade-offs and the ongoing research into ways to better handle the downsides of strong encryption.</p> <h4 id="internet--blockchain-voting"><!>Internet / Blockchain Voting</h4> <p>Internet voting on the blockchain keeps getting shredded by security researchers. There were two talks in the conference on different systems and countries. The first country, Switzerland, aborted plans to use online voting after researchers found a multitude of issues. The second country, Russia, pushed forward and did it anyway, including major protocol changes pushed out two days before the election.</p> <p>Quote of the day: âThanks to us, they now have a reinforced door on a house made of cardboard,â said Pierrick Gaudry regarding the Moscow voting scheme. Oh, and the blockchain that was used in this one completely disappeared a few hours after the election was over.</p> <p><!></p> <h3 id="on-side-channel-attacks"><!>On Side-channel Attacks</h3> <p>Once thought to be impractical for real-world attacks, side channels are the gift that keeps on giving. If youâre not familiar with this class of attack, basically it encompasses anything that involves observation of some facet of a running machine, such as the power usage, how fast some request is processed, the sound of fans, or whatever, and leverages that information to extract cryptographic keys.</p> <p>The conference had a host of presentations showing just how practical these attacks can be.</p> <p>For all of these attacks, using crypto code that is invariant in regards to secret dataâââthat is, software with no if statements, variable length loops, etc., if that code does any operations using private cryptographic keysâââis the best solution. Then code pathways are always the same, timing is the same, caches are the same, and nothing can be learned through side-channels. <!> library uses constant-time code. So does <!>. Sadly, very little else is built this way, mainly because itâs very difficult. And here are some of the consequences:</p> <h4 id="trusted-platform-modulestpms"><!>Trusted Platform Modules (TPMs)</h4> <p>These are chips inside your computer or other device meant to securely hold onto secrets and protect the operating system. These are meant to be resistant to hardware and software attacks. Unfortunately, the bulk of deployed TPMs come from two manufacturers: Intel and STMicroelectronics. Researchers <!> using practical side channels.</p> <h4 id="pseudo-random-number-generators"><!>Pseudo-Random Number Generators</h4> <p>In computing, when we go to use a random number, weâre actually using some small amount of hopefully random entropy as input, and a function that produces a long stream of random-looking output. This is a Pseudo-Random Number Generator (PRNG) and with regards to cryptography, these are everywhere.</p> <p>This year I learned that these, too, can be subject to side-channel attacks. And in many cases, if you can reverse the PRNG, you can break the crypto without breaking the crypto. Ouch.</p> <h4 id="spectre"><!>SPECTRE</h4> <p>SPECTRE is a class of attacks that were in the news a lot a couple of years ago. It stands for âspeculative executionâ and takes advantage of an optimization in CPUs that has them calculate results down two branches of code before discarding one of them as a way to speed up processing. Attackers figured out how to exploit this by indirectly testing the cache for the branches not takenâââbranches that should be illegal to take.</p> <p>The talk on SPECTRE was frightening because the bottom line from it is this: we havenât yet fixed the problem and we donât have any line of sight to getting it fixed either. Some pieces are better now, but others still arenât. Not only that, but new attacks like <!> make it practical to remotely exploit the problem. And if you combine that with distributed SSL termination endpoints like the ones hosted by Google, Amazon, Cloudflare, etc., the result is wholesale theft of private SSL keys. Scary!</p> <h3 id="on-privacy-preserving-protocols"><!>On Privacy Preserving Protocols</h3> <h4 id="apple-find-myservice"><!>Apple âFind Myâ Service</h4> <p>An Engineer from Apple explained how they help people find devices using all iOS devices everywhere as âfindersâ reporting whatâs around them without compromising the privacy of the âfinderâ or the devices being found.</p> <p>Today, your device has to be alive and connected to the Internet when you go to the âFind Myâ service to see where your devices are at. You effectively send them all a message saying âwhere you at?â and a map displays the results as they come in. If they come in.</p> <p>The core idea in their new approach is to have rotating key pairs that are deterministic in nature. So if you want to search for your device, you can know what key pairs it will use for any 15-minute time block. The public key is the broadcast identifier. Finder devices encrypt a location to the public key when a beacon is seen. Only one of your devices can see what location was encrypted. Apple sees things like IP addresses but promises not to store that information for long (and they likely have other services with lower privacy guarantees in that regard).</p> <p><!> Appleâs privacy-preserving device location tracker</p> <h4 id="facebook-messenger"><!>Facebook Messenger</h4> <p>
1Facebook seems pretty serious about making Messenger end-to-end encrypted and to bring all of the features of the current Messenger along in privacy-preserving variants. Today, they have a âsecretâ mode, but it only works for one-on-one and without many features like the ability to share photos.</p> <p>This talk was more a discussion of the requirements and problem statements. It seems theyâre still early in the process and likely years away from delivering here. But theyâre saying the right things, even if those statements are only scoped to Messenger and not the broader platform. Here are some quotes that caught my attention:</p> <ul><li>âWhile Facebook has traditionally focused on creating a small town square, with Messenger, we want to create an intimate living room.â</li> <li>âPrivacy is a human right.â</li> <li>âHaving strong end-to-end privacy guarantees is a top goal.â</li> <li>âGetting security right is a scaling challenge.â</li> <li>âMore engineers writing more code just makes more opportunities for bugs to be introduced.â</li> <li>âNeed frameworks and APIs that are secure by default.â</li> <li>âWe are going to ship this⦠this is happening.â</li></ul> <h4 id="stolen-passwordchecks"><!>Stolen Password Checks</h4> <p>Google presented on how they preserve privacy while letting someone check to see if their username and password has been compromised and is available on the âdark web.â Immediately after they described their system, there was a presentation on flaws in their first protocol and in approaches by some similar services.</p> <p>Passwords, like English, have frequency distributions, and a surprising amount of data can be reversed because of that fact.</p> <p>Googleâs basic approach is to put sets of hashed username and password combos into buckets that share a hash prefix and then to ship back more results than are necessary. They use expensive hashing algorithms (Argon2) to make it expensive for someone to essentially extract information out of their list of 4 billion compromised usernames and passwords.</p> <p>The work on attacking the service suggested putting results in multiple buckets to smooth out the frequency.</p> <h4 id="mozilla-site-blocking-telemetry"><!>Mozilla Site Blocking Telemetry</h4> <p>Mozilla wants to collect information on what their block lists are blocking or not in the real world. But that information can leak info about a personâs browsing habits. So theyâve cooked up a mechanism that reports a boolean, for each site on the block list, on whether or not it was blocked that day one or more times. Then that information is split into two parts that, when added together, will result in either a one or a zero and the two parts are sent to two different servers operated by independent entities. Between them, they can come up with aggregates without learning any individual value.</p> <p>It gets fancier in order to protect against a malicious client that wants to mess up the stats, but the most interesting thing is the struggle theyâve had at taking a split trust approach. Theyâre still searching for an entity willing to help run one of the collection points, but who is completely independent, hosted on a different platform (ie, not also AWS), and in a different country/legal jurisdiction. And even then, itâs hard to guarantee someone wonât get access to both sets of data or the entities wonât collude.</p> <h3 id="on-the-insecurity-of-new-communications-standards"><!>On the (In)security of New Communications Standards</h3> <h4 id="5g"><!>5G</h4> <p>If youâre like me, you mostly think about 5G as new infrastructure, new radio frequency range, and as bringing faster speeds. But itâs a new protocol too, and itâs supposed to bring better privacy and security in the face of IMSI Catcher devices and other common attacks against todayâs 4G/LTE.</p> <p>Unfortunately, there are a bunch of problems. In particular, the protocol does a good job of preventing someone from tracking you, except if they can trigger an error. And with that error condition, you become fully trackable. Fixing it ârequires a major redesign.â Doh. Some of the other discovered issues have already been fixed.</p> <p>As a side note, this talk was a win for formal verification methods, which is to say, formally modeling a protocol and having computers apply attack models to the protocol model to find problems.</p> <h4 id="wpa3"><!>WPA3</h4> <p>The Dragonblood attack against WPA3 wins the award for the best attack name of the conference. Itâs another side-channel attack, but more relevant to this section. Suffice to say that researchers keep getting more clever on how to exploit non-constant time code. In this case, a networkâs password, which is used to derive a session key, derived that key in non-constant time. Using a dictionary, attackers were able to profile timings, adjust another parameter (MAC address), and thereafter by passively observing timings they could quickly figure out the network password. The protocol designers were told of the potential issue early on but dismissed it as not a practical attack. Oops.</p> <h3 id="on-therest"><!>
1On the Rest</h3> <ul><li>There are a lot of really cool <!> that allow you to code in a high-level language and compile down to something usable. Sadly, most of them are hard to use and poorly documented/written by academics. Still, a few are good and worth a closer look.</li> <li>The author of the book Applied Cryptography argued that most symmetric algorithms use more rounds than necessary for the risk models and that lowering them would have a negligible impact on risk while having a big speedup in performance. I had the distinct impression that most of the cryptographers in the audience like extra margins in their security and werenât buying what he was selling. Odds of NIST reducing security requirements? Very long.</li> <li>Secret sharing, where keys get split into multiple parts and n of m parties have to come together to decrypt something, have been stuck in the relative dark ages ignoring all of the progress on symmetric algorithms over the years. So improvements like Associated Data, Authentication, Nonces, etc. are missing from the key shares, which means they can get corrupted or worse. Sadly, there is no implementation of the speakerâs proposed modern approach, which sounded very promising.</li></ul> <h3 id="summary"><!>Summary</h3> <p>This got long and I didnât even touch on half the talks. Real World Crypto is a deeply technical conference that focuses on solutions to concrete problems that work in practiceâââand thatâs very exciting.</p> <p>We desperately need more of these solutions and they need to be more widely available for use in a broader array of applications. Weâve all lost control of our dataâââpeople and businesses alikeâââbut we can choose to vote with our wallets and back the businesses that invest the time and money required to develop applications that are private by design and by default.</p>',1);function bt(K,V){const X=Be(V,["children","$$slots","$$events","$$legacy"]);Re(K,Ge(()=>X,()=>J,{children:(Y,rt)=>{var H=ot(),c=o(Oe(H),4),Z=n(c);i(Z,{"aria-hidden":"true",tabindex:"-1",href:"#on-things-that-arebroken",children:(e,h)=>{var t=je();s(e,t)},$$slots:{default:!0}}),a(),r(c);var p=o(c,2),ee=n(p);i(ee,{"aria-hidden":"true",tabindex:"-1",href:"#tls-12-andbelow",children:(e,h)=>{var t=Ee();s(e,t)},$$slots:{default:!0}}),a(),r(p);var u=o(p,2),te=o(n(u));i(te,{href:"https://www.icir.org/johanna/papers/imc18tlsdeployment.pdf",rel:"nofollow",children:(e,h)=>{a();var t=d("but the pace of adoption is much faster");s(e,t)},$$slots:{default:!0}}),a(),r(u);var m=o(u,2),ae=o(n(m));i(ae,{href:"https://eprint.iacr.org/2018/1173.pdf",rel:"nofollow",children:(e,h)=>{a();var t=d("timing attacks against TLS");s(e,t)},$$slots:{default:!0}}),a(),r(m);var f=o(m,2),oe=n(f);i(oe,{"aria-hidden":"true",tabindex:"-1",href:"#sha-1",children:(e,h)=>{var t=Le();s(e,t)},$$slots:{default:!0}}),a(),r(f);var g=o(f,2),re=o(n(g));i(re,{href:"https://eprint.iacr.org/2020/014.pdf",rel:"nofollow",children:(e,h)=>{a();var t=d("yet another attack");s(e,t)},$$slots:{default:!0}}),a(),r(g);var y=o(g,2),ne=n(y);i(ne,{"aria-hidden":"true",tabindex:"-1",href:"#ocb2",children:(e,h)=>{var t=qe();s(e,t)},$$slots:{default:!0}}),a(),r(y);var v=o(y,2),se=o(n(v));i(se,{href:"https://eprint.iacr.org/2018/1090",rel:"nofollow",children:(e,h)=>{a();var t=d("full plain text recovery attack");s(e,t)},$$slots:{default:!0}}),a(),r(v);var w=o(v,2),ie=n(w);N(ie,{src:"/images/blog/1__LKQPvd33B2afrToqG__JXHQ.jpeg",alt:"A cryptanalytic frenzy on OCB2"}),a(),r(w);var b=o(w,2),he=n(b);i(he,{"aria-hidden":"true",tabindex:"-1",href:"#unnamed-hardware-security-modulevendor",children:(e,h)=>{var t=ze();s(e,t)},$$slots:{default:!0}}),a(),r(b);var k=o(b,6),le=o(n(k));i(le,{href:"https://i.blackhat.com/USA-19/Thursday/us-19-Campana-Everybody-Be-Cool-This-Is-A-Robbery.pdf",rel:"nofollow",children:(e,h)=>{a();var t=d("researchers showed");s(e,t)},$$slots:{default:!0}}),a(),r(k);var $=o(k,2),de=n($);i(de,{"aria-hidden":"true",tabindex:"-1",href:"#the-encryption-wars",children:(e,h)=>{var t=We();s(e,t)},$$slots:{default:!0}}),a(),r($);var _=o($,10),ce=n(_);i(ce,{"aria-hidden":"true",tabindex:"-1",href:"#internet--blockchain-voting",children:(e,h)=>{var t=Fe();s(e,t)},$$slots:{default:!0}}),a(),r(_);var x=o(_,6),pe=n(x);N(pe,{src:"/images/blog/1__ssSDX2MtaaQ6nWtfrQ27rQ.jpeg"}),r(x);var P=o(x,2),ue=n(P);i(ue,{"aria-hidden":"true",tabindex:"-1",href:"#on-side-channel-attacks",children:(e,h)=>{var t=Ne();s(e,t)},$$slots:{default:!0}}),a(),r(P);var T=o(P,6),U=o(n(T));i(U,{href:"https://github.com/ironcorelabs/recrypt-rs",rel:"nofollow",children:(e,h)=>{a();var t=d("IronCoreâs recrypt-rs");s(e,t)},$$slots:{default:!0}});var me=o(U,2);i(me,{href:"https://bearssl.org/",rel:"nofollow",children:(e,h)=>{a();var t=d("BearSSL");s(e,t)},$$slots:{default:!0}}),a(),r(T);var S=o(T,2),fe=n(S);i(fe,{"aria-hidden":"true",tabindex:"-1",href:"#trusted-platform-modulestpms",children:(e,h)=>{var t=He();s(e,t)},$$slots:{default:!0}}),a(),r(S);var A=o(S,2),ge=o(n(A));i(ge,{href:"https://tpm.fail/",rel:"nofollow",children:(e,h)=>{a();var t=d("broke both of these");s(e,t)},$$slots:{default:!0}}),a(),r(A);var I=o(A,2),ye=n(I);i(ye,{"aria-hidden":"true",tabindex:"-1",href:"#pseudo-random-number-generators",children:(e,h)=>{var t=Ue();s(e,t)},$$slots:{default:!0}}),a(),r(I);var C=o(I,6),ve=n(C);i(ve,{"aria-hidden":"true",tabindex:"-1",href:"#spectre",children:(e,h)=>{var t=De();s(e,t)},$$slots:{default:!0}}),a(),r(C);var M=o(C,4),we=o(n(M));i(we,{href:"https://misc0110.net/web/files/netspectre.pdf",rel:"nofollow",children:(e,h)=>{a();var t=d("NetSpectre");s(e,t)},$$slots:{default:!0}}),a(),r(M);var B=o(M,2),be=n(B);i(be,{"aria-hidden":"true",tabindex:"-1",href:"#on-privacy-preserving-protocols",children:(e,h)=>{var t=Qe();s(e,t)},$$slots:{default:!0}}),a(),r(B);var G=o(B,2),ke=n(G);
1i(ke,{"aria-hidden":"true",tabindex:"-1",href:"#apple-find-myservice",children:(e,h)=>{var t=Je();s(e,t)},$$slots:{default:!0}}),a(),r(G);var O=o(G,8),$e=n(O);N($e,{src:"/images/blog/1__Yv__iCTl6R9mzo__JRStrZ1A.jpeg",alt:"Apple's privacy-preserving device location tracker"}),a(),r(O);var R=o(O,2),_e=n(R);i(_e,{"aria-hidden":"true",tabindex:"-1",href:"#facebook-messenger",children:(e,h)=>{var t=Ke();s(e,t)},$$slots:{default:!0}}),a(),r(R);var j=o(R,8),xe=n(j);i(xe,{"aria-hidden":"true",tabindex:"-1",href:"#stolen-passwordchecks",children:(e,h)=>{var t=Ve();s(e,t)},$$slots:{default:!0}}),a(),r(j);var E=o(j,10),Pe=n(E);i(Pe,{"aria-hidden":"true",tabindex:"-1",href:"#mozilla-site-blocking-telemetry",children:(e,h)=>{var t=Xe();s(e,t)},$$slots:{default:!0}}),a(),r(E);var L=o(E,6),Te=n(L);i(Te,{"aria-hidden":"true",tabindex:"-1",href:"#on-the-insecurity-of-new-communications-standards",children:(e,h)=>{var t=Ye();s(e,t)},$$slots:{default:!0}}),a(),r(L);var q=o(L,2),Se=n(q);i(Se,{"aria-hidden":"true",tabindex:"-1",href:"#5g",children:(e,h)=>{var t=Ze();s(e,t)},$$slots:{default:!0}}),a(),r(q);var z=o(q,8),Ae=n(z);i(Ae,{"aria-hidden":"true",tabindex:"-1",href:"#wpa3",children:(e,h)=>{var t=et();s(e,t)},$$slots:{default:!0}}),a(),r(z);var W=o(z,4),Ie=n(W);i(Ie,{"aria-hidden":"true",tabindex:"-1",href:"#on-therest",children:(e,h)=>{var t=tt();s(e,t)},$$slots:{default:!0}}),a(),r(W);var F=o(W,2),D=n(F),Ce=o(n(D));i(Ce,{href:"https://github.com/MPC-SoK/frameworks",rel:"nofollow",children:(e,h)=>{a();var t=d("multi-party computation frameworks");s(e,t)},$$slots:{default:!0}}),a(),r(D),a(4),r(F);var Q=o(F,2),Me=n(Q);i(Me,{"aria-hidden":"true",tabindex:"-1",href:"#summary",children:(e,h)=>{var t=at();s(e,t)},$$slots:{default:!0}}),a(),r(Q),a(4),s(Y,H)},$$slots:{default:!0}}))}export{bt as component};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.