PING

Testing post quantum cryptography in DNSSEC


Listen Later

This time on PING, Peter Thomassen from deSEC and Jason Goertzen from Sandbox AQ discuss their research project on post quantum cryptography in DNSSEC, funded by NLNet Labs.


Post Quantum cryptography is a response to the risk that a future quantum computer will be able to implement Shor's Algorithm -a mechanism to uncover the private key in the RSA public-private key cryptographic mechanism, as well as Diffie-Hellman and Elliptic Curve methods. This would render all existing public-private based security useless, because with knowledge of the private key by a third party, the ability to sign uniquely over things is lost: DNSSEC doesn't depend on secrecy of messages but it does depend on RSA and elliptic curve signatures. We'd lose trust in the DNSSEC protections the private key provides.

Post Quantum Cryptography (PQC) addresses this by implementing methods which are not exposed to the weakness that Shor's Algorithm can exploit. But, the cost and complexity of these PQC methods rises.


Peter and Jason have been exploring implementations of some of the NIST candidate post quantum algorithms, deployed into bind9 and PowerDNS code. They've been able to use the Atlas system to test how reliably the signed contents can be seen in the DNS and have confirmed that some aspects of packet size in the DNS, and new algorithms will be a problem in deployment as things stand.


As they note, it's too soon to move this work into IETF DNS standards process but there is a continuing interest in researching the space, with other activity underway from SIDN which we'll also feature on PING.

...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,999 Listeners

Radiolab by WNYC Studios

Radiolab

43,900 Listeners

Risky Business by Patrick Gray

Risky Business

370 Listeners

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,182 Listeners

Talk Python To Me by Michael Kennedy

Talk Python To Me

584 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

215 Listeners

Click Here by Recorded Future News

Click Here

416 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,971 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

33 Listeners

The Hedge by Russ White

The Hedge

16 Listeners

Signals and Threads by Jane Street

Signals and Threads

74 Listeners

The RIPE Labs Podcast by RIPE Labs Editor

The RIPE Labs Podcast

1 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

59 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

319 Listeners