Founder of the Dutch Web Alliance Development in PHP, Python, C, Java. Lead developer of Saffire. Blog: http://adayinthelifeof.nl Email: [email protected] Twitter: @jaytaph
SHIFT 13 Message: C O D E Ciphertext (key=1): D P E F Ciphertext (key=2): E Q F G Ciphertext (key=-1): B M C D Ciphertext (key=0): C O D E Ciphertext (key=26): C O D E Ciphertext (key=52): C O D E http://upload.wikimedia.org/wikipedia/commons/thumb/2/2b/Caesar3.svg
any other language) can be represented by a percentage. ➡ ‘E’ is used 12.7% of the times in english texts, the ‘Z’ only 0.074%. ➡ ‘E’ is used 17.4% of the times in german texts, the ‘Q’ only 0.022% 15
by a military court for a crime they didn't commit. These men promptly escaped from a maximum-security stockade to the Los Angeles underground. Today, still wanted by the government, they survive as soldiers of fortune. If you have a problem, if no one else can help and if you can find them, maybe you can hire, The A- Team. 20 http://gutenberg.spiegel.de/buch/3664/4 Decrypted message:
can decrypt. - message is only for Alice = encryption 28 Encrypt with private key: - only public key can decrypt. - message is guaranteed coming for Alice = signing
small and large messages. ✗ need to send over the key to the other side. Asymmetrical ✓ no need to send over the (whole) key. ✓ can be used for encryption and validation (signing). ✗ very resource intensive. ✗ only useful for small messages. 29
practically impossible to refactor a large number back into 2 separate prime numbers Prime number is only divisible by 1 and itself: 2, 3, 5, 7, 11, 13, 17, 19 etc... 34
quickly. But nowadays we have to assume it’s possible by some, but not (yet) many. ➡ Brute-force decrypting is always lurking around (quicker/more machines, better algorithms). ➡ Better (pubkey) algorithms already exists! 36
(large) prime number (but not too close to p) ➡ n = p . q (bit length of the RSA key) ➡ φ = (p-1) . (q-1) (the φ thingie is called phi) ➡ e = gcd(e, φ) = 1 ➡ d = (d . e) mod φ = 1
φ) = 1 ==> gcd(3, 20) = 1 41 Fermat number: 2 + 1 2 n Fermat prime: Fermat nr that is also prime: 3, 5, 17, 257, 65537 Study shows that 98.5% of the time 65537 is used P = 11 | Q = 3 | N = 33 | Phi = 20 | e = ? | d = ?
but before encryption, with random padding bytes shown in green: 0002257F48FD1F1793B7E5E02306F2D3228F5C95ADF5F31566729F132AA12009 E3FC9B2B475CD6944EF191E3F59545E671E474B555799FE3756099F044964038 B16B2148E9A2F9C6F44BB5C52E3C6C8061CF694145FAFDB24402AD1819EACEDF 4A36C6E4D2CD8FC1D62E5A1268F496004E636AF98E40F3ADCFCCB698F4E80B9F After RSA encryption, the output is: 3D2AB25B1EB667A40F504CC4D778EC399A899C8790EDECEF062CD739492C9CE5 8B92B9ECF32AF4AAC7A61EAEC346449891F49A722378E008EFF0B0A8DBC6E621 EDC90CEC64CF34C640F5B36C48EE9322808AF8F4A0212B28715C76F3CB99AC7E 609787ADCE055839829E0142C44B676D218111FFE69F9D41424E177CBA3A435B http://www.di-mgt.com.au/rsa_alg.html#pkcs1schemes 50
know for sure that nobody has read this email (before it came to us?) ➡ Do we know for sure that the contents of the message isn’t tampered with? ➡ We use signing! Questions: 54
the validity of a message. ➡ Like md5 or sha1, so when the message changes, so will the signature. ➡ This works on the premise that Alice and only Alice has the private key that can create the signature. Signing a message 55
the server (highest possible encryption used). ➡ Symmetric encryption (AES-256, others) ➡ But both sides needs the same key, so we have the same problem as before: how do we send over the key? 59
which one to use. ➡ Server send certificate(s). ➡ Client sends “session key” encrypted by the public key found in the server certificate. ➡ Server and client uses the “session key” for symmetrical encryption. 62
secondary (better!?) encryption. ➡ SSL/TLS is a separate talk (it’s way more complex as this) ➡ http://www.moserware.com/2009/06/first-few- milliseconds-of-https.html 63
secure, and it WILL fail. ➡ Encryption is as strong as the weakest link, which 9 out of 10 times will be you. ➡ Encryptions evolve. Do not use today what you used 10 years ago. ➡ Every encryption will become obsolete! ➡ Always follow the best practices. 67