February 19, 2007

Crypto Expert: Moore's Law fuels app obesity epidemic

Chip advances fuel "supersized," insecure applications

Cryptography is no mean field. After all, the science was invented by humans for the purpose of concealing information from other humans. That means that the best cryptographers have to be blindingly smart, with a mastery of mathematics but also a firm grasp of human psychology and, these days, fields such as computer science.

Paul Kocher, president and chief scientist of Cryptography Research is a good example of the breed. A cryptography superstar, Kocher is credited with helping discover two different techniques for defeating certain kinds of encryption algorithms. He’s also a corporate executive who’s devoted his life to helping create cryptographic applications that can be used in the real world.

Kocher sat down to talk security with InfoWorld Senior Editor Paul F. Roberts at the recent RSA Security Conference in San Francisco. Despite making his name by poking holes in encryption, Kocher says that crypto hacks are the last thing enterprise IT should worry about. A much bigger problem is wrestling with the security implications of application and OS “supersizing” that is being fueled by a new generation of powerful processors.

InfoWorld: Tell us a bit about the history of Cryptography Research and how the security environment has changed since you first started the company.

Paul Kocher: I started Cryptography Research 11 years ago. When I first started working on these problems, we were still at the point where you could understand how systems work. This was back in the DOS days. You had 640K of memory and could run one program at a time. These days, I have no clue what’s running on my laptop. And you probably have no idea, either. There’s too much software there. Moore’s Law has created obesity in systems, so when you’re trying to come up with ways to keep things secret despite this, it’s an enormous problem.

IW: Cryptography is often followed as a kind of arms race, with people who want to make stronger encryption pitted against those who want to break it. Is that the wrong discussion to have?

PK: There are a few pieces that are strong. The math behind modern algorithms is incredibly robust. That’s the thing most people focus on: “We have this brick and it’s really strong, so if we have a system that includes this brick, it will also be really strong.” But implementations are where the problems lie. People tend to get enamored with the cryptography and the algorithms and not pay attention to other things that end up failing.

IW: You talk about the “brittleness” in much of application security. If you were an enterprise shop with internally developed applications, what steps would you take to reduce that brittleness?

PK: One thing I’d do is just step back and have the engineers think about how they would attack the system. It’s a different mind set than how to build features. You start looking for that thread that lets you in, and you learn something useful. Also, try to build your application so that it doesn’t need sophisticated security capabilities. If you’ve got an application on the Web where it’s exposed to outside attacks, just leave the feature out that’s going to create the risks.

Close

On Twitter now

Applications

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Applications Resource Alerts

Subscribe to the Applications Newsletter

Stay informed of the latest news and technologies around application, project and performance management.

White paper

Turn Your IT Department into a Lean Machine

Like any valuable resource, IT is a terrible thing to waste. But by applying the same lean techniques that have been used to streamline manufacturing processes, IT departments can reduce costs, improve performance and better manage resources.

Download now! »

Podcast

Economy Makes Automation a Must-Have Tech for 2009

Stephen Elliot, vice president of strategy for CA's Infrastructure Management and Data Center Automation business unit, explains why difficult economic times drive the need for simplified management capabilities and advanced automation tools.

Listen now! »

White paper

What You Need to Know About Virtual Infrastructure Management - Now

According to a recent study CA conducted with 300 CIOs and top IT executives, 64 percent of respondents say they've already invested in virtualization, and the other 36 percent reported that they plan to invest in virtualization.

Download now! »

Webcast

Leveraging Virtualization and Process Automation

In this video learn about process automation in a virtualized world. How CA and VMware are enabling enterprise datacenter automation.

View now! »
©1994-2009 Infoworld, Inc.