1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,420
we're going to cover cryptographic attacks.

3
00:00:03,420 --> 00:00:04,740
Now, cryptographic attacks

4
00:00:04,740 --> 00:00:07,470
refer to techniques and strategies that adversaries employ

5
00:00:07,470 --> 00:00:10,230
to exploit vulnerabilities in cryptographic systems

6
00:00:10,230 --> 00:00:12,450
with the intent to compromise the confidentiality,

7
00:00:12,450 --> 00:00:15,240
integrity, and authenticity of your data.

8
00:00:15,240 --> 00:00:16,410
These attacks are there

9
00:00:16,410 --> 00:00:18,330
to defeat the cryptographic protections,

10
00:00:18,330 --> 00:00:19,950
either by deciphering encrypted data

11
00:00:19,950 --> 00:00:22,740
without the appropriate key, impersonating another user,

12
00:00:22,740 --> 00:00:25,230
or creating forgeries that cryptographic systems

13
00:00:25,230 --> 00:00:26,850
would deem authentic.

14
00:00:26,850 --> 00:00:28,920
These methods can range from exploiting weaknesses

15
00:00:28,920 --> 00:00:30,900
in cryptographic algorithms and protocols

16
00:00:30,900 --> 00:00:33,270
to leveraging flaws in software implementations

17
00:00:33,270 --> 00:00:36,270
or simply using brute-force techniques to guess the key.

18
00:00:36,270 --> 00:00:38,250
For our purposes in this lesson, though,

19
00:00:38,250 --> 00:00:40,950
we're going to focus on attacks related to downgrade attacks,

20
00:00:40,950 --> 00:00:43,530
collision attacks, and the threat of quantum computing

21
00:00:43,530 --> 00:00:44,363
that is looming over

22
00:00:44,363 --> 00:00:46,770
all of our existing encryption algorithms.

23
00:00:46,770 --> 00:00:49,140
Now, first we have downgrade attacks.

24
00:00:49,140 --> 00:00:51,510
At its core, a cryptographic downgrade attack,

25
00:00:51,510 --> 00:00:53,580
also known as a version rollback attack,

26
00:00:53,580 --> 00:00:55,500
will aim to force a system to use a weaker

27
00:00:55,500 --> 00:00:57,750
or older cryptographic standard or protocol

28
00:00:57,750 --> 00:00:59,520
than what it's currently using.

29
00:00:59,520 --> 00:01:01,230
The idea here is that by rolling back

30
00:01:01,230 --> 00:01:02,670
to these outdated versions,

31
00:01:02,670 --> 00:01:05,220
an attacker can exploit known vulnerabilities or weaknesses

32
00:01:05,220 --> 00:01:07,770
in those older protocols that have now been addressed

33
00:01:07,770 --> 00:01:09,960
in newer or more secure versions.

34
00:01:09,960 --> 00:01:11,370
For example, let's pretend

35
00:01:11,370 --> 00:01:13,290
that we have two people, Alice and Bob,

36
00:01:13,290 --> 00:01:15,150
and they want to establish a secure connection channel

37
00:01:15,150 --> 00:01:16,590
between their systems.

38
00:01:16,590 --> 00:01:18,510
Now, most modern cryptographic systems

39
00:01:18,510 --> 00:01:20,790
will support multiple versions of a protocol

40
00:01:20,790 --> 00:01:22,440
to ensure for backwards compatibility

41
00:01:22,440 --> 00:01:24,240
with older legacy systems.

42
00:01:24,240 --> 00:01:26,280
When Alice and Bob begin their handshake

43
00:01:26,280 --> 00:01:28,050
to establish that secure connection,

44
00:01:28,050 --> 00:01:29,910
their systems will typically communicate

45
00:01:29,910 --> 00:01:30,900
the version of the protocols

46
00:01:30,900 --> 00:01:32,490
that each one of them can support,

47
00:01:32,490 --> 00:01:33,870
and then their systems will agree

48
00:01:33,870 --> 00:01:35,340
to use the most secure version

49
00:01:35,340 --> 00:01:37,650
that both of these systems can understand.

50
00:01:37,650 --> 00:01:40,200
For example, if I speak English and Spanish

51
00:01:40,200 --> 00:01:42,090
and you speak Spanish and Chinese,

52
00:01:42,090 --> 00:01:43,710
we would agree to speak Spanish

53
00:01:43,710 --> 00:01:46,230
because both of us understand that language.

54
00:01:46,230 --> 00:01:47,940
So going back to our example,

55
00:01:47,940 --> 00:01:50,310
let's pretend that we have an attacker named Eve,

56
00:01:50,310 --> 00:01:52,500
and she wants to be able to intercept this communication

57
00:01:52,500 --> 00:01:54,060
between Alice and Bob.

58
00:01:54,060 --> 00:01:55,170
To execute this attack,

59
00:01:55,170 --> 00:01:57,210
Eve will try to manipulate the messages being sent

60
00:01:57,210 --> 00:02:00,090
between Alice and Bob's computer to establish this handshake

61
00:02:00,090 --> 00:02:02,010
and decide on a version to use.

62
00:02:02,010 --> 00:02:03,960
This way, they can manipulate the message

63
00:02:03,960 --> 00:02:06,120
to say the highest version that both parties support

64
00:02:06,120 --> 00:02:08,910
is in fact an older, less secure version.

65
00:02:08,910 --> 00:02:12,390
Now, Alice and Bobs' systems, unaware of Eve's interference,

66
00:02:12,390 --> 00:02:14,400
will proceed with the outdated protocol,

67
00:02:14,400 --> 00:02:16,830
and this makes all their communications susceptible

68
00:02:16,830 --> 00:02:19,200
to vulnerabilities inherent in that older version

69
00:02:19,200 --> 00:02:20,550
of the encryption algorithm

70
00:02:20,550 --> 00:02:22,410
that Eve can now take advantage of

71
00:02:22,410 --> 00:02:25,230
to be able to see everything they're sending back and forth.

72
00:02:25,230 --> 00:02:26,760
One infamous real-world example

73
00:02:26,760 --> 00:02:28,200
of this type of downgrade attack

74
00:02:28,200 --> 00:02:30,450
involves the use of the POODLE attack,

75
00:02:30,450 --> 00:02:31,770
known as the Padding Oracle

76
00:02:31,770 --> 00:02:33,990
On Downgraded Legacy Encryption attack,

77
00:02:33,990 --> 00:02:36,660
which targeted SSL version 3.0.

78
00:02:36,660 --> 00:02:38,040
Now, despite the availability

79
00:02:38,040 --> 00:02:41,580
and widespread use of a more secure protocol like TLS,

80
00:02:41,580 --> 00:02:44,010
many systems still supported SSL 3.0

81
00:02:44,010 --> 00:02:45,930
for backward compatibility.

82
00:02:45,930 --> 00:02:48,480
POODLE tried to exploit this by forcing its victims

83
00:02:48,480 --> 00:02:51,240
to revert to this older, more insecure protocol,

84
00:02:51,240 --> 00:02:52,290
and this would allow attackers

85
00:02:52,290 --> 00:02:55,140
to extract sensitive data from these communications.

86
00:02:55,140 --> 00:02:58,290
So, why are downgrade attacks so dangerous?

87
00:02:58,290 --> 00:03:00,030
Well, these downgrade attacks are dangerous

88
00:03:00,030 --> 00:03:02,850
because they turn the very nature of evolving security,

89
00:03:02,850 --> 00:03:04,440
such as the development of a stronger,

90
00:03:04,440 --> 00:03:07,740
more robust cryptographic protocol, against itself.

91
00:03:07,740 --> 00:03:10,290
In trying to be more inclusive and comprehensive,

92
00:03:10,290 --> 00:03:12,570
our systems that maintain this backwards compatibility

93
00:03:12,570 --> 00:03:15,540
with older standards are unknowingly leaving themselves open

94
00:03:15,540 --> 00:03:17,580
to these types of downgrade attacks.

95
00:03:17,580 --> 00:03:19,530
But it's not all doom and gloom.

96
00:03:19,530 --> 00:03:20,850
Awareness of downgrade attacks

97
00:03:20,850 --> 00:03:22,380
has led to the development of countermeasures

98
00:03:22,380 --> 00:03:23,550
to help prevent them.

99
00:03:23,550 --> 00:03:26,070
For instance, many systems have phased out support

100
00:03:26,070 --> 00:03:29,310
for legacy protocols that are known to be truly insecure,

101
00:03:29,310 --> 00:03:32,850
even if it means sacrificing backward compatibility.

102
00:03:32,850 --> 00:03:35,340
In other scenarios, version intolerance checks

103
00:03:35,340 --> 00:03:38,250
can also be employed where a system tests the waters

104
00:03:38,250 --> 00:03:39,930
by initially claiming to only support

105
00:03:39,930 --> 00:03:41,940
the most recent protocol version.

106
00:03:41,940 --> 00:03:42,960
If the other end user

107
00:03:42,960 --> 00:03:44,940
truly doesn't support the latest version,

108
00:03:44,940 --> 00:03:46,950
they will naturally respond accordingly,

109
00:03:46,950 --> 00:03:49,530
but if there's any interference forcing a downgrade,

110
00:03:49,530 --> 00:03:51,630
this will quickly become apparent.

111
00:03:51,630 --> 00:03:53,970
Second, we have collision attacks.

112
00:03:53,970 --> 00:03:56,730
Now, a collision attack aims to find two different inputs

113
00:03:56,730 --> 00:03:58,890
that produce the same hash output.

114
00:03:58,890 --> 00:04:00,000
This can be a vulnerability

115
00:04:00,000 --> 00:04:03,060
because hashing is commonly used for data verification.

116
00:04:03,060 --> 00:04:05,070
For example, when you're downloading a file

117
00:04:05,070 --> 00:04:07,620
from the internet, the website may provide a hash value

118
00:04:07,620 --> 00:04:08,880
for that file.

119
00:04:08,880 --> 00:04:10,560
Once you finish downloading the file,

120
00:04:10,560 --> 00:04:12,270
you can run it through a hash algorithm

121
00:04:12,270 --> 00:04:14,370
and calculate a new hash digest.

122
00:04:14,370 --> 00:04:15,720
Then you compare that

123
00:04:15,720 --> 00:04:17,670
to the one that's listed on the website.

124
00:04:17,670 --> 00:04:19,560
If they match, it's assumed that the file

125
00:04:19,560 --> 00:04:21,000
has not been tampered with.

126
00:04:21,000 --> 00:04:23,670
However, if an attacker can produce a malicious file

127
00:04:23,670 --> 00:04:26,310
with the same hash value by exploiting a collision,

128
00:04:26,310 --> 00:04:27,930
the user could be tricked into thinking

129
00:04:27,930 --> 00:04:29,220
they have a legitimate file

130
00:04:29,220 --> 00:04:32,190
when in fact they have a file that has the same hash value,

131
00:04:32,190 --> 00:04:34,470
which means it's subject to a collision.

132
00:04:34,470 --> 00:04:38,430
Historically, MD5, also known as Message Digest Algorithm 5,

133
00:04:38,430 --> 00:04:40,230
was a popular hashing function.

134
00:04:40,230 --> 00:04:41,850
However, over the years,

135
00:04:41,850 --> 00:04:43,680
many vulnerabilities in its structure

136
00:04:43,680 --> 00:04:46,170
made collision attacks much more feasible.

137
00:04:46,170 --> 00:04:48,270
Cybersecurity researchers were eventually able

138
00:04:48,270 --> 00:04:49,800
to create two different sequences

139
00:04:49,800 --> 00:04:52,320
that hashed out to the same MD5 hash,

140
00:04:52,320 --> 00:04:54,720
rendering MD5 unsuitable for further use

141
00:04:54,720 --> 00:04:57,900
in security certificates and encryption technologies.

142
00:04:57,900 --> 00:04:59,970
These collisions do undermine the trust

143
00:04:59,970 --> 00:05:02,340
and reliability placed on cryptographic tools,

144
00:05:02,340 --> 00:05:04,260
and they could potentially allow malicious actors

145
00:05:04,260 --> 00:05:07,320
to impersonate trusted entities, forge digital signatures,

146
00:05:07,320 --> 00:05:10,470
or distribute tampered data while appearing genuine.

147
00:05:10,470 --> 00:05:12,930
Now, the "Birthday Paradox" or "Birthday Attack"

148
00:05:12,930 --> 00:05:15,240
is a counterintuitive probability theory

149
00:05:15,240 --> 00:05:16,410
that plays a significant role

150
00:05:16,410 --> 00:05:18,300
in understanding collision attacks.

151
00:05:18,300 --> 00:05:22,200
The paradox itself posits that in a group of just 23 people,

152
00:05:22,200 --> 00:05:23,700
there's a better than even chance

153
00:05:23,700 --> 00:05:26,190
that two of them share the same birthday.

154
00:05:26,190 --> 00:05:27,900
Translating this to cryptography,

155
00:05:27,900 --> 00:05:30,060
the "Birthday Attack" refers to the probability

156
00:05:30,060 --> 00:05:32,370
that two distinct inputs or files,

157
00:05:32,370 --> 00:05:34,770
when processed through the same hashing function,

158
00:05:34,770 --> 00:05:38,010
will produce the same output, which we call a collision.

159
00:05:38,010 --> 00:05:39,180
Due to this principle,

160
00:05:39,180 --> 00:05:41,070
finding collisions in a hashing function

161
00:05:41,070 --> 00:05:43,680
might be more probable than initially perceived.

162
00:05:43,680 --> 00:05:45,090
For cryptographic systems,

163
00:05:45,090 --> 00:05:47,850
especially hashing algorithms with a fixed size output,

164
00:05:47,850 --> 00:05:51,690
like MD5, SHA-1, SHA-256, and SHA-3,

165
00:05:51,690 --> 00:05:53,760
this means that vulnerabilities to collisions

166
00:05:53,760 --> 00:05:55,590
might arise faster than expected,

167
00:05:55,590 --> 00:05:57,240
and this underscores the necessity

168
00:05:57,240 --> 00:05:58,800
for robust cryptographic designs

169
00:05:58,800 --> 00:06:00,870
and frequent algorithm updates.

170
00:06:00,870 --> 00:06:03,150
Third, we need to talk about quantum computing

171
00:06:03,150 --> 00:06:04,020
and the threat it poses

172
00:06:04,020 --> 00:06:07,200
to our current cryptographic implementations and algorithms.

173
00:06:07,200 --> 00:06:09,420
Before we dive into the threat of quantum computing,

174
00:06:09,420 --> 00:06:11,400
we need to take a moment to define it.

175
00:06:11,400 --> 00:06:13,320
Now, quantum computing involves a computer

176
00:06:13,320 --> 00:06:14,640
that uses quantum mechanics

177
00:06:14,640 --> 00:06:17,610
to generate and manipulate quantum bits, known as qubits,

178
00:06:17,610 --> 00:06:20,340
in order to access enormous processing power.

179
00:06:20,340 --> 00:06:21,870
Now, I know this is a weird definition

180
00:06:21,870 --> 00:06:23,520
because in the definition itself,

181
00:06:23,520 --> 00:06:25,440
I'm using two terms inside of it,

182
00:06:25,440 --> 00:06:27,450
both quantum and computing.

183
00:06:27,450 --> 00:06:30,000
And in this case, I really don't like that definition,

184
00:06:30,000 --> 00:06:32,760
but there really is no better way to explain this.

185
00:06:32,760 --> 00:06:34,830
Now, when you think about a classic computer

186
00:06:34,830 --> 00:06:36,960
like the one you're watching this course on right now,

187
00:06:36,960 --> 00:06:39,900
it's using ones and zeros to process information.

188
00:06:39,900 --> 00:06:41,640
The faster you can flip those bits

189
00:06:41,640 --> 00:06:44,220
and turn a one to a zero, or a zero to a one,

190
00:06:44,220 --> 00:06:46,890
that means the faster you can get information done

191
00:06:46,890 --> 00:06:49,410
and the faster computer you have overall.

192
00:06:49,410 --> 00:06:50,520
Well, at a certain point,

193
00:06:50,520 --> 00:06:52,440
we can't make our computers any faster

194
00:06:52,440 --> 00:06:54,090
by simply flipping bits.

195
00:06:54,090 --> 00:06:56,460
This means we've run out of computing capability.

196
00:06:56,460 --> 00:07:00,210
So to overcome that, we started taking single processors

197
00:07:00,210 --> 00:07:01,950
and putting in dual processors.

198
00:07:01,950 --> 00:07:04,680
And then we made quad processors, which had four cores,

199
00:07:04,680 --> 00:07:07,530
and then we made octa-core processors that had eight cores,

200
00:07:07,530 --> 00:07:10,560
and things like that as we kept speeding up our computers.

201
00:07:10,560 --> 00:07:11,880
Well, with quantum computing,

202
00:07:11,880 --> 00:07:13,860
it is a completely different ball game.

203
00:07:13,860 --> 00:07:15,510
Instead of using ones and zeros,

204
00:07:15,510 --> 00:07:18,180
we use things known as quantum bits, or qubits,

205
00:07:18,180 --> 00:07:21,450
and this can be done in computing or in communications.

206
00:07:21,450 --> 00:07:23,010
Now, when we deal with communications,

207
00:07:23,010 --> 00:07:25,080
we're talking about quantum communications

208
00:07:25,080 --> 00:07:26,550
being a communications network

209
00:07:26,550 --> 00:07:29,100
that relies on using qubits made of photons,

210
00:07:29,100 --> 00:07:30,210
or in our case, light,

211
00:07:30,210 --> 00:07:31,650
to send multiple combinations

212
00:07:31,650 --> 00:07:33,480
of ones and zeros simultaneously,

213
00:07:33,480 --> 00:07:35,160
which will result in tamper-resistant

214
00:07:35,160 --> 00:07:37,230
and extremely fast communications.

215
00:07:37,230 --> 00:07:39,150
Again, I know this is really vague,

216
00:07:39,150 --> 00:07:41,370
but hang in with me here for just a second.

217
00:07:41,370 --> 00:07:42,690
When we talk about quantum,

218
00:07:42,690 --> 00:07:44,910
I keep talking about these things called qubits,

219
00:07:44,910 --> 00:07:46,380
and I talk about the fact that there's a difference

220
00:07:46,380 --> 00:07:48,030
between our traditional electrons,

221
00:07:48,030 --> 00:07:50,340
which are either on or off, ones or zeros,

222
00:07:50,340 --> 00:07:52,080
and this thing called a qubit.

223
00:07:52,080 --> 00:07:54,480
So let's talk about a qubit for a moment.

224
00:07:54,480 --> 00:07:55,950
What exactly is it?

225
00:07:55,950 --> 00:07:58,680
Well, a qubit is really just a quantum bit.

226
00:07:58,680 --> 00:08:01,110
It's composed of either electrons or photons,

227
00:08:01,110 --> 00:08:03,750
so it can either be electrical or made by light,

228
00:08:03,750 --> 00:08:06,870
and it can represent numerous combinations of ones and zeros

229
00:08:06,870 --> 00:08:10,560
at the same time using something known as superpositioning.

230
00:08:10,560 --> 00:08:12,180
Now, this is really the main benefit

231
00:08:12,180 --> 00:08:15,300
of using a quantum computer over a traditional computer

232
00:08:15,300 --> 00:08:17,880
because we're not just going to have a single one or zero.

233
00:08:17,880 --> 00:08:20,310
You can have multiple combinations of ones or zeros

234
00:08:20,310 --> 00:08:23,610
at the same time, and this would all be one qubit.

235
00:08:23,610 --> 00:08:24,630
So you can actually crunch through

236
00:08:24,630 --> 00:08:27,810
a wide variety of potential outcomes simultaneously.

237
00:08:27,810 --> 00:08:30,420
And so it's really great when you're trying to do a bunch

238
00:08:30,420 --> 00:08:32,370
of really complex math problems,

239
00:08:32,370 --> 00:08:33,480
and that's really the whole reason

240
00:08:33,480 --> 00:08:35,429
that we have quantum computing.

241
00:08:35,429 --> 00:08:36,929
When you think about quantum computing,

242
00:08:36,929 --> 00:08:39,390
it's never going to replace the computer on your desktop.

243
00:08:39,390 --> 00:08:41,220
That is not what it's designed for.

244
00:08:41,220 --> 00:08:44,159
Instead, it's designed for very specific use cases,

245
00:08:44,159 --> 00:08:45,900
such as very complex math problems

246
00:08:45,900 --> 00:08:48,240
or trying to do something like modeling of an atom

247
00:08:48,240 --> 00:08:51,120
or some kind of atomic structure, or something like that.

248
00:08:51,120 --> 00:08:52,980
Now, why should I care about quantum

249
00:08:52,980 --> 00:08:54,090
if it's never going to be something

250
00:08:54,090 --> 00:08:55,620
that's sitting on my desktop?

251
00:08:55,620 --> 00:08:57,420
Well, because there's one thing that quantum

252
00:08:57,420 --> 00:08:59,130
is really, really good at.

253
00:08:59,130 --> 00:09:01,380
And what is that? It's math problems.

254
00:09:01,380 --> 00:09:03,870
And if you think about cryptography, all cryptography is

255
00:09:03,870 --> 00:09:06,390
is a bunch of really complex math problems.

256
00:09:06,390 --> 00:09:08,370
And so because cryptography is used

257
00:09:08,370 --> 00:09:10,050
to secure our communications and our data

258
00:09:10,050 --> 00:09:12,630
by relying on how difficult a math problem is to compute,

259
00:09:12,630 --> 00:09:15,300
with a traditional computer, this is actually something

260
00:09:15,300 --> 00:09:17,340
that gives us strength in cryptography.

261
00:09:17,340 --> 00:09:19,020
But if quantum computers are really good

262
00:09:19,020 --> 00:09:20,100
at doing math problems,

263
00:09:20,100 --> 00:09:22,320
and they can do it much, much faster,

264
00:09:22,320 --> 00:09:25,050
that means our cryptography can actually be defeated

265
00:09:25,050 --> 00:09:27,630
and taken down by a quantum computer.

266
00:09:27,630 --> 00:09:29,760
And this is why we have to start thinking about this,

267
00:09:29,760 --> 00:09:30,720
because it's one of the things

268
00:09:30,720 --> 00:09:33,900
we rely so heavily on in cryptography is the key exchange

269
00:09:33,900 --> 00:09:36,000
using asymmetric communications.

270
00:09:36,000 --> 00:09:37,110
Now, one way we do that

271
00:09:37,110 --> 00:09:38,940
is with the public key infrastructure.

272
00:09:38,940 --> 00:09:41,310
Well, that whole concept is that we have to have a way

273
00:09:41,310 --> 00:09:44,670
to do a simple math problem to create a very complex thing

274
00:09:44,670 --> 00:09:47,370
that has a difficult time of being broken back apart.

275
00:09:47,370 --> 00:09:50,010
So for example, if I take two prime numbers

276
00:09:50,010 --> 00:09:52,470
and I multiply them together and I give you the result,

277
00:09:52,470 --> 00:09:54,810
that result is really easy to calculate

278
00:09:54,810 --> 00:09:56,760
if you know what the two prime numbers are

279
00:09:56,760 --> 00:09:58,530
to be able to multiply them together.

280
00:09:58,530 --> 00:10:01,470
This would be, in our case, a public and private key

281
00:10:01,470 --> 00:10:04,350
that really represent two really large prime numbers.

282
00:10:04,350 --> 00:10:06,330
Now, once you have that result, though,

283
00:10:06,330 --> 00:10:07,890
it might be a really large number,

284
00:10:07,890 --> 00:10:10,410
but there's only two things that can be factored into it,

285
00:10:10,410 --> 00:10:12,720
those two keys, the public and private key

286
00:10:12,720 --> 00:10:13,980
that I just gave you.

287
00:10:13,980 --> 00:10:16,170
Those are our two prime numbers.

288
00:10:16,170 --> 00:10:17,760
Well, with quantum computing,

289
00:10:17,760 --> 00:10:20,610
they can make very quick work of this type of math problem,

290
00:10:20,610 --> 00:10:22,200
whereas our traditional computers can't

291
00:10:22,200 --> 00:10:24,150
because it'd involve taking that big number

292
00:10:24,150 --> 00:10:26,280
and dividing it by one and then dividing by two

293
00:10:26,280 --> 00:10:27,300
and then dividing by three

294
00:10:27,300 --> 00:10:29,520
and then dividing by five, then dividing by seven,

295
00:10:29,520 --> 00:10:31,770
and keep going until we get all the prime numbers

296
00:10:31,770 --> 00:10:33,360
and find the two factors.

297
00:10:33,360 --> 00:10:34,770
Well, with quantum computing,

298
00:10:34,770 --> 00:10:36,060
we don't have to do it that way.

299
00:10:36,060 --> 00:10:38,940
Instead, this becomes a relatively easy math problem,

300
00:10:38,940 --> 00:10:40,890
and we can crack it much, much quicker

301
00:10:40,890 --> 00:10:42,360
with a quantum computer.

302
00:10:42,360 --> 00:10:44,640
In fact, asymmetric encryption algorithms,

303
00:10:44,640 --> 00:10:46,920
which are those that rely on this hard math problem,

304
00:10:46,920 --> 00:10:48,330
have been mathematically proven

305
00:10:48,330 --> 00:10:50,430
to be broken by quantum computers.

306
00:10:50,430 --> 00:10:51,660
Now, the good news here

307
00:10:51,660 --> 00:10:53,550
is that at the time of me saying this,

308
00:10:53,550 --> 00:10:56,700
there are no real operational quantum computers in use.

309
00:10:56,700 --> 00:10:58,200
In fact, the only quantum computers

310
00:10:58,200 --> 00:10:59,610
at the time of me saying this

311
00:10:59,610 --> 00:11:01,860
are ones being used for prototyping and development

312
00:11:01,860 --> 00:11:03,540
on a very small scale,

313
00:11:03,540 --> 00:11:05,100
and governments and large companies

314
00:11:05,100 --> 00:11:07,410
are the ones who are spending enormous sums of money

315
00:11:07,410 --> 00:11:10,170
to create these small-scale quantum computers.

316
00:11:10,170 --> 00:11:11,460
Right now, the estimate

317
00:11:11,460 --> 00:11:13,440
is that we won't have a working quantum computer

318
00:11:13,440 --> 00:11:16,770
until at least 2030 for government and large corporate use.

319
00:11:16,770 --> 00:11:18,330
But consumers like you and I

320
00:11:18,330 --> 00:11:19,860
won't see quantum computers available

321
00:11:19,860 --> 00:11:23,550
until sometime in the late 2030s or early 2040s.

322
00:11:23,550 --> 00:11:25,440
But it is something we need to be aware of

323
00:11:25,440 --> 00:11:27,060
because our current encryption algorithms

324
00:11:27,060 --> 00:11:30,300
are not made to withstand the power of quantum computing.

325
00:11:30,300 --> 00:11:32,370
So, that brings us to this idea

326
00:11:32,370 --> 00:11:34,740
of how do you overcome quantum computers

327
00:11:34,740 --> 00:11:36,420
when you're dealing with cryptography?

328
00:11:36,420 --> 00:11:39,120
And that is post-quantum cryptography.

329
00:11:39,120 --> 00:11:40,590
Now, post-quantum cryptography

330
00:11:40,590 --> 00:11:42,720
is a new kind of cryptographic algorithm

331
00:11:42,720 --> 00:11:45,540
that can be implemented using today's classic computers

332
00:11:45,540 --> 00:11:47,760
but would still be impervious to attacks

333
00:11:47,760 --> 00:11:49,350
from future quantum computers

334
00:11:49,350 --> 00:11:52,140
once they're in production and they are widely available.

335
00:11:52,140 --> 00:11:53,550
Now, there's really two methods that we use

336
00:11:53,550 --> 00:11:56,370
to try to create this post-quantum cryptography world.

337
00:11:56,370 --> 00:11:58,800
The first method is to just increase our key size

338
00:11:58,800 --> 00:12:00,810
and to increase the number of permutations that are needed

339
00:12:00,810 --> 00:12:02,040
to be brute-forced.

340
00:12:02,040 --> 00:12:03,150
This works well when you're dealing

341
00:12:03,150 --> 00:12:05,730
with symmetric encryption algorithms like AES.

342
00:12:05,730 --> 00:12:07,680
If I take AES-128

343
00:12:07,680 --> 00:12:10,350
and I increase it to AES-256, for example,

344
00:12:10,350 --> 00:12:14,790
I have doubled my key length from 128 bits to 256 bits.

345
00:12:14,790 --> 00:12:16,470
But I have actually squared

346
00:12:16,470 --> 00:12:18,030
the number of possible combinations

347
00:12:18,030 --> 00:12:19,260
that are going to have to be figured out

348
00:12:19,260 --> 00:12:21,810
by that quantum computer, and this extends the time

349
00:12:21,810 --> 00:12:24,270
and makes it much stronger and harder to crack.

350
00:12:24,270 --> 00:12:27,300
The other way we do this is by working on other approaches,

351
00:12:27,300 --> 00:12:29,700
and researchers are doing that right now.

352
00:12:29,700 --> 00:12:32,760
These are called post-quantum resistant algorithms.

353
00:12:32,760 --> 00:12:34,620
Now, these things are going to be looking at using things

354
00:12:34,620 --> 00:12:36,540
like lattice-based cryptography

355
00:12:36,540 --> 00:12:39,210
and supersingular isogeny key exchanges.

356
00:12:39,210 --> 00:12:40,650
Now again, both of these terms

357
00:12:40,650 --> 00:12:42,180
are not something you need to understand

358
00:12:42,180 --> 00:12:43,530
or go in depth on.

359
00:12:43,530 --> 00:12:45,510
In fact, when we talk about quantum computing

360
00:12:45,510 --> 00:12:46,890
and quantum communications,

361
00:12:46,890 --> 00:12:48,330
we really need to think about qubits

362
00:12:48,330 --> 00:12:50,880
and all the stuff we're talking about with the word quantum.

363
00:12:50,880 --> 00:12:52,200
And I just want you to associate this

364
00:12:52,200 --> 00:12:54,540
with something that can be really easy to break apart

365
00:12:54,540 --> 00:12:57,120
our asymmetric encryption algorithms pretty quickly

366
00:12:57,120 --> 00:13:00,480
once it's in production, but it doesn't exist today yet.

367
00:13:00,480 --> 00:13:02,700
Remember, asymmetric encryption algorithms

368
00:13:02,700 --> 00:13:04,350
are the things that we use for key exchanges

369
00:13:04,350 --> 00:13:07,320
and digital signatures in a public key infrastructure,

370
00:13:07,320 --> 00:13:08,610
and that's really where the threat is

371
00:13:08,610 --> 00:13:10,980
when we start talking about quantum computers.

372
00:13:10,980 --> 00:13:12,990
Again, right now, we do not have

373
00:13:12,990 --> 00:13:15,750
any dedicated quantum resistant cryptography yet,

374
00:13:15,750 --> 00:13:17,700
but in 2022,

375
00:13:17,700 --> 00:13:19,710
the National Institute of Science and Technology

376
00:13:19,710 --> 00:13:21,720
did complete a six-year competition

377
00:13:21,720 --> 00:13:24,030
to select post-quantum cryptographic standards,

378
00:13:24,030 --> 00:13:26,970
and they ended up selecting four viable algorithms.

379
00:13:26,970 --> 00:13:28,560
For your general encryption needs,

380
00:13:28,560 --> 00:13:31,560
NIST recommends that you use the CRYSTALS-Kyber algorithm,

381
00:13:31,560 --> 00:13:33,900
which uses a relatively small encryption key

382
00:13:33,900 --> 00:13:36,030
and is focused on the difficulty of solving learning

383
00:13:36,030 --> 00:13:38,730
with error problems over modular lattices

384
00:13:38,730 --> 00:13:40,770
to provide a post-quantum encryption algorithm

385
00:13:40,770 --> 00:13:41,730
that is roughly equivalent

386
00:13:41,730 --> 00:13:45,300
to the strength of our current AES 256-based algorithms

387
00:13:45,300 --> 00:13:47,190
used in symmetric encryption.

388
00:13:47,190 --> 00:13:48,390
For digital signatures,

389
00:13:48,390 --> 00:13:51,030
NIST recommends you select one of three algorithms,

390
00:13:51,030 --> 00:13:54,930
either the CRYSTALS-Dilithium, FALCON, or SPHINCS+,

391
00:13:54,930 --> 00:13:57,630
although NIST does recommend CRYSTALS-Dilithium

392
00:13:57,630 --> 00:14:00,840
as the primary post-quantum digital signature algorithm.

393
00:14:00,840 --> 00:14:03,120
All these algorithms do focus on the difficulty

394
00:14:03,120 --> 00:14:06,180
of solving structured lattices except for SPHINCS+,

395
00:14:06,180 --> 00:14:09,120
which instead focuses on the use of hashing functions.

396
00:14:09,120 --> 00:14:11,730
So remember, when it comes to cryptographic attacks,

397
00:14:11,730 --> 00:14:13,860
there are three main types that you need to consider.

398
00:14:13,860 --> 00:14:15,990
These are downgrade attacks, collision attacks,

399
00:14:15,990 --> 00:14:17,910
and the threat of quantum computing.

400
00:14:17,910 --> 00:14:19,860
A cryptographic downgrade attack is used

401
00:14:19,860 --> 00:14:21,540
to force a system into using a weaker

402
00:14:21,540 --> 00:14:23,820
or older cryptographic standard or protocol

403
00:14:23,820 --> 00:14:25,470
than what it's currently using.

404
00:14:25,470 --> 00:14:27,330
A collision attack is going to be used

405
00:14:27,330 --> 00:14:28,590
to find two different inputs

406
00:14:28,590 --> 00:14:30,450
that produce the same hash output

407
00:14:30,450 --> 00:14:31,830
by using the principles demonstrated

408
00:14:31,830 --> 00:14:33,540
by the Birthday Paradox.

409
00:14:33,540 --> 00:14:35,100
Quantum computing, on the other hand,

410
00:14:35,100 --> 00:14:36,900
is more at the theoretical stage today

411
00:14:36,900 --> 00:14:38,070
than the practical stage,

412
00:14:38,070 --> 00:14:40,440
and it harnesses the principles of quantum mechanics

413
00:14:40,440 --> 00:14:43,350
to process vast amounts of information simultaneously

414
00:14:43,350 --> 00:14:44,340
in order to enable it

415
00:14:44,340 --> 00:14:46,860
to potentially break traditional encryption algorithms

416
00:14:46,860 --> 00:14:50,580
like RSA and ECC in just a few seconds

417
00:14:50,580 --> 00:14:52,860
by rapidly factoring large prime numbers

418
00:14:52,860 --> 00:14:55,290
or solving discreet logarithmic problems.

419
00:14:55,290 --> 00:14:57,630
Since this capability threatens the foundational security

420
00:14:57,630 --> 00:14:58,950
of our current digital communication

421
00:14:58,950 --> 00:15:00,420
and data storage systems,

422
00:15:00,420 --> 00:15:02,400
it is one that you should continually read up on

423
00:15:02,400 --> 00:15:04,200
and study over the next few years

424
00:15:04,200 --> 00:15:06,720
as quantum computing and post-quantum algorithms

425
00:15:06,720 --> 00:15:08,100
begin to become a larger part

426
00:15:08,100 --> 00:15:10,143
of our enterprise systems and networks.

