Certificates | Computer Security
So far we’ve seen powerful techniques for securing communication such that the only information we must carefully protect regards “keys” of various sorts. Given the success of cryptography in general, arguably the biggest challenge remaining for its effective use concerns exactly those keys, and how to manage them. For instance, how does Alice find out Bob’s public key? Does it matter? Suppose Alice wants to communicate securely with Bob over an insecure communication channel, but she doesn’t know his public key (and he doesn’t know hers). A naive strategy is that she could just send Bob a message asking him to send his public key, and accept whatever response she gets back (over the insecure communication channel). Alice would then encrypt her message using the public key she received in this way. This naive approach is insecure. An active attacker (Mallory, in our usual terminology) could tamper with Bob’s response, replacing the public key in Bob’s response with the attacker’s publi
Certificates | Computer Security Skip to main content Menu Expand (external link) Document Search Copy Copied Computer Security 13. Certificates So far we’ve seen powerful techniques for securing communication such that the only information we must carefully protect regards “keys” of various sorts. Given the success of cryptography in general, arguably the biggest challenge remaining for its effective use concerns exactly those keys, and how to manage them. For instance, how does Alice find out Bob’s public key? Does it matter? 13.1. Man-in-the-middle Attacks Suppose Alice wants to communicate
Explore this link on the map →related reading
- Everything you should know about certificates and PKI but are too afraid to asksmallstep.com
- Public key infrastructure - Wikipediaen.wikipedia.org
- Public-key cryptography - Wikipediaen.wikipedia.org
- TLS | Computer Securitytextbook.cs161.org
- Digital hygiene – karpathykarpathy.bearblog.dev
- A Post-Quantum Future for Let's Encrypt - Let's Encryptletsencrypt.org
- The Cryptographer Who Ensures We Can Trust Our Computers | Quanta Magazinequantamagazine.org
- Diffie–Hellman key exchange - Wikipediaen.wikipedia.org
- Zero Knowledge Proofs: An illustrated primer – A Few Thoughts on Cryptographic Engineeringblog.cryptographyengineering.com
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- Digital Signatures | Computer Securitytextbook.cs161.org
- Quartz — Modemmodemworks.com