1
00:00:06,540 --> 00:00:07,890
- Welcome to lesson four,

2
00:00:07,890 --> 00:00:09,360
Explain the Importance of Using

3
00:00:09,360 --> 00:00:12,060
Appropriate Cryptographic Solutions.

4
00:00:12,060 --> 00:00:15,510
Now, this is a first of many
lessons about cryptography,

5
00:00:15,510 --> 00:00:17,100
and, as I mentioned in the intro,

6
00:00:17,100 --> 00:00:19,140
really one of my favorite topics.

7
00:00:19,140 --> 00:00:21,150
You may find this topic to be challenging,

8
00:00:21,150 --> 00:00:22,560
so just kinda stick with it.

9
00:00:22,560 --> 00:00:24,870
And if it doesn't resonate the first time,

10
00:00:24,870 --> 00:00:27,180
don't hesitate to go through the lessons

11
00:00:27,180 --> 00:00:29,460
one more time, two more
times, three more times,

12
00:00:29,460 --> 00:00:32,070
until, all of a sudden,
you have that aha moment

13
00:00:32,070 --> 00:00:34,170
and you're like, "Oh yeah, I get it now."

14
00:00:34,170 --> 00:00:37,803
So we're gonna start off in
4.1 with a cryptography primer.

15
00:00:39,180 --> 00:00:40,710
Now, traditional cryptography,

16
00:00:40,710 --> 00:00:42,570
and traditional cryptography goes

17
00:00:42,570 --> 00:00:44,790
way back into ancient times,

18
00:00:44,790 --> 00:00:46,710
is a conversion of communication

19
00:00:46,710 --> 00:00:50,190
into a form that can only be
read by the intended recipient.

20
00:00:50,190 --> 00:00:52,680
I want you to imagine, in ancient times,

21
00:00:52,680 --> 00:00:54,120
a massive battle going on

22
00:00:54,120 --> 00:00:56,280
and we've got generals on both sides.

23
00:00:56,280 --> 00:00:58,710
And one general wants to get a message

24
00:00:58,710 --> 00:01:00,480
to his frontline troops,

25
00:01:00,480 --> 00:01:02,970
but really worried that
what if the messenger

26
00:01:02,970 --> 00:01:06,750
got captured and got sent
to the other general,

27
00:01:06,750 --> 00:01:09,840
would they be able to read the message?

28
00:01:09,840 --> 00:01:12,810
And so they wanted to have some way

29
00:01:12,810 --> 00:01:14,850
to make that message unreadable,

30
00:01:14,850 --> 00:01:18,513
and that was a traditional
application of cryptography.

31
00:01:20,400 --> 00:01:21,600
Now, modern cryptography

32
00:01:21,600 --> 00:01:24,330
has really widened that
historical definition

33
00:01:24,330 --> 00:01:27,390
to also include the
assurance of integrity,

34
00:01:27,390 --> 00:01:28,860
that the message is trustworthy,

35
00:01:28,860 --> 00:01:31,380
that it hasn't been
changed in transmission,

36
00:01:31,380 --> 00:01:32,940
and sender identity.

37
00:01:32,940 --> 00:01:35,490
We know exactly who
that message came from.

38
00:01:35,490 --> 00:01:38,460
When we talk about
cryptography from a high level,

39
00:01:38,460 --> 00:01:40,400
we'll use the term PKI.

40
00:01:40,400 --> 00:01:42,750
It stands for public key Infrastructure.

41
00:01:42,750 --> 00:01:45,600
And public key infrastructure
really encompasses

42
00:01:45,600 --> 00:01:49,560
all of the programs, the
data formats, the procedures

43
00:01:49,560 --> 00:01:53,070
the communication protocols,
the security policies,

44
00:01:53,070 --> 00:01:55,500
and the public key
cryptographic mechanisms

45
00:01:55,500 --> 00:01:58,440
that work together in
a comprehensive manner

46
00:01:58,440 --> 00:02:01,053
to enable secure communication.

47
00:02:04,110 --> 00:02:07,470
So I wanna introduce you to
four cryptographic solutions

48
00:02:07,470 --> 00:02:11,010
and, most importantly, their use case,

49
00:02:11,010 --> 00:02:14,100
encryption, hashing, digital signatures,

50
00:02:14,100 --> 00:02:15,870
and digital certificates.

51
00:02:15,870 --> 00:02:16,980
Now, in this lesson,

52
00:02:16,980 --> 00:02:18,780
I'm just gonna introduce
you to each of them,

53
00:02:18,780 --> 00:02:21,360
and then we will do lessons
specifically on that.

54
00:02:21,360 --> 00:02:23,550
We have a lesson on encryption,
a lesson on hashing,

55
00:02:23,550 --> 00:02:25,620
a lesson on digital signatures,

56
00:02:25,620 --> 00:02:28,023
and a lesson on digital certificates.

57
00:02:29,280 --> 00:02:32,010
Encryption is a process
of encoding information.

58
00:02:32,010 --> 00:02:34,080
It's really making information unreadable.

59
00:02:34,080 --> 00:02:35,700
When you open up and
you look at the message,

60
00:02:35,700 --> 00:02:36,930
you're like, "That's gibberish.

61
00:02:36,930 --> 00:02:38,130
What does it mean?"

62
00:02:38,130 --> 00:02:41,673
So the use case of encryption
is confidentiality.

63
00:02:42,630 --> 00:02:44,910
Hashing is a one-way function

64
00:02:44,910 --> 00:02:49,380
that turns a file or a string
of text into a unique digest,

65
00:02:49,380 --> 00:02:51,090
sometimes called a fingerprint,

66
00:02:51,090 --> 00:02:55,260
which is just a number a bunch
of values of the message.

67
00:02:55,260 --> 00:02:58,653
Now, the use case for hashing
is going to be integrity.

68
00:03:00,150 --> 00:03:02,010
Then we have digital signatures.

69
00:03:02,010 --> 00:03:04,710
Digital signature's actually a hash value

70
00:03:04,710 --> 00:03:07,050
that's been encrypted with
the sender's private key.

71
00:03:07,050 --> 00:03:08,310
That sounds a little confusing right now.

72
00:03:08,310 --> 00:03:09,630
Don't worry about it.

73
00:03:09,630 --> 00:03:11,250
What you need to know right now

74
00:03:11,250 --> 00:03:13,440
is the use case is sender authenticity

75
00:03:13,440 --> 00:03:15,300
that we know who the sender was,

76
00:03:15,300 --> 00:03:17,220
and non-repudiation,

77
00:03:17,220 --> 00:03:20,670
that the sender cannot deny
that they sent the message.

78
00:03:20,670 --> 00:03:22,680
And then we have digital certificates.

79
00:03:22,680 --> 00:03:25,290
And digital certificates
is a digital object

80
00:03:25,290 --> 00:03:27,780
that is tied to a cryptographic key pair.

81
00:03:27,780 --> 00:03:29,880
We haven't talked about
this yet, so don't worry.

82
00:03:29,880 --> 00:03:32,160
But the use case for a digital certificate

83
00:03:32,160 --> 00:03:33,480
is authentication.

84
00:03:33,480 --> 00:03:35,700
It's how we can authenticate someone.

85
00:03:35,700 --> 00:03:37,770
When a server says, "I am this server,"

86
00:03:37,770 --> 00:03:40,110
when the code says, "I am this code,"

87
00:03:40,110 --> 00:03:42,240
when the patch says, "I am this code,"

88
00:03:42,240 --> 00:03:44,647
it will be from their digital
certificate that we can say,

89
00:03:44,647 --> 00:03:47,850
"Okay, you are who you say you are."

90
00:03:47,850 --> 00:03:51,090
So encryption for confidentiality,
hashing for integrity,

91
00:03:51,090 --> 00:03:52,860
digital signatures for sender

92
00:03:52,860 --> 00:03:55,020
authentication and non-repudiation,

93
00:03:55,020 --> 00:03:57,693
and digital certificates
for authentication.

94
00:04:01,020 --> 00:04:03,960
We've got lots of terms to
go through in this lesson.

95
00:04:03,960 --> 00:04:06,780
We're gonna start with talking
about what a cipher is.

96
00:04:06,780 --> 00:04:10,620
A cipher is just a technique
that transforms plain text

97
00:04:10,620 --> 00:04:13,980
into cipher text and back to plain text.

98
00:04:13,980 --> 00:04:16,170
We have had cipher since ancient times.

99
00:04:16,170 --> 00:04:17,580
The Caesar cipher was just

100
00:04:17,580 --> 00:04:20,400
move every character three places over.

101
00:04:20,400 --> 00:04:25,290
So we would substitute a D
for an A, and an E for a B.

102
00:04:25,290 --> 00:04:27,450
So it's just the technique that allows us

103
00:04:27,450 --> 00:04:29,790
to transform our plain
text into cipher text

104
00:04:29,790 --> 00:04:32,400
and back to plain text.

105
00:04:32,400 --> 00:04:34,470
Plain text is just human readable text.

106
00:04:34,470 --> 00:04:36,750
It's what you see on
your screen right now.

107
00:04:36,750 --> 00:04:39,570
Cipher text is either
text that's been encrypted

108
00:04:39,570 --> 00:04:41,760
or in some form is human unreadable.

109
00:04:41,760 --> 00:04:44,733
It's it's letters, but it
doesn't mean anything to you.

110
00:04:46,020 --> 00:04:50,160
An algorithm is nothing
more than a mathematically

111
00:04:50,160 --> 00:04:52,950
complex modern cipher.

112
00:04:52,950 --> 00:04:53,783
I'll say that again,

113
00:04:53,783 --> 00:04:57,210
an algorithm is a mathematically
complex modern cipher

114
00:04:57,210 --> 00:04:59,433
that we need to have a computer to solve.

115
00:05:00,690 --> 00:05:02,970
Now, algorithms are generally well known.

116
00:05:02,970 --> 00:05:04,083
They're published.

117
00:05:04,944 --> 00:05:07,410
They're really public information.

118
00:05:07,410 --> 00:05:09,870
A key, also called a crypto variable,

119
00:05:09,870 --> 00:05:13,710
is going to be a secret value
that we use with an algorithm.

120
00:05:13,710 --> 00:05:16,470
Because if everybody knows
what the algorithm is,

121
00:05:16,470 --> 00:05:18,090
then how do we use it for secrecy.

122
00:05:18,090 --> 00:05:19,680
We have to have a secret component.

123
00:05:19,680 --> 00:05:21,660
And the secret component that we use

124
00:05:21,660 --> 00:05:23,400
in conjunction with the algorithm

125
00:05:23,400 --> 00:05:25,293
is going to be known as a key.

126
00:05:26,670 --> 00:05:28,830
Now, a stream cipher is
going to be a cipher,

127
00:05:28,830 --> 00:05:30,120
remember, that's just a technique

128
00:05:30,120 --> 00:05:34,080
that transforms plain text
into cipher text and back,

129
00:05:34,080 --> 00:05:37,500
is an algorithm that works
on one bit of data at a time,

130
00:05:37,500 --> 00:05:39,750
using these XOR functions.

131
00:05:39,750 --> 00:05:42,240
When I have to imagine a stream cipher,

132
00:05:42,240 --> 00:05:44,490
I always think of a
faucet that's dripping.

133
00:05:44,490 --> 00:05:46,920
Drip, drip, drip.

134
00:05:46,920 --> 00:05:50,040
And each of those drips in
my mind is one bit at a time.

135
00:05:50,040 --> 00:05:53,910
And so my algorithm would work
on each one of those drip.

136
00:05:53,910 --> 00:05:56,100
Drip, drip.

137
00:05:56,100 --> 00:05:57,720
A block cipher is an algorithm

138
00:05:57,720 --> 00:05:59,280
that works with a block of data.

139
00:05:59,280 --> 00:06:03,750
Could be a 56k block,
64k block, 128k block,

140
00:06:03,750 --> 00:06:06,183
could be a 256k block.

141
00:06:07,350 --> 00:06:09,183
It's just a block of data.

142
00:06:10,260 --> 00:06:13,950
Confusion is a process of changing values.

143
00:06:13,950 --> 00:06:16,020
So complex substitution functions

144
00:06:16,020 --> 00:06:18,090
are used to create confusion.

145
00:06:18,090 --> 00:06:22,470
And lastly, diffusion is the
process of changing the order.

146
00:06:22,470 --> 00:06:25,890
So sending bits through
multiple rounds of transposition

147
00:06:25,890 --> 00:06:27,873
is used to create diffusion.

148
00:06:29,460 --> 00:06:30,750
Okay, so I just introduced you to key.

149
00:06:30,750 --> 00:06:32,490
Let's talk more about a key.

150
00:06:32,490 --> 00:06:35,820
A key is a secret value
used with an algorithm.

151
00:06:35,820 --> 00:06:36,660
The key can dictate

152
00:06:36,660 --> 00:06:38,460
what parts of the algorithm
are gonna be used,

153
00:06:38,460 --> 00:06:40,740
in what order, and with what values.

154
00:06:40,740 --> 00:06:42,930
'Cause remember, the
algorithms are published.

155
00:06:42,930 --> 00:06:43,920
They're known.

156
00:06:43,920 --> 00:06:47,550
So the key is what provides
the secret part of it.

157
00:06:47,550 --> 00:06:49,920
Now, when you hear the term key space,

158
00:06:49,920 --> 00:06:53,430
it's really just the number
of possible key combinations.

159
00:06:53,430 --> 00:06:57,990
So a 256 bit key is two
to the 256 bit power.

160
00:06:57,990 --> 00:07:00,450
That's a lot of combinations.

161
00:07:00,450 --> 00:07:03,000
Because a key is really just a value.

162
00:07:03,000 --> 00:07:05,400
It's really just a set of numbers.

163
00:07:05,400 --> 00:07:09,570
So two to the 256, lots of options there.

164
00:07:09,570 --> 00:07:11,880
Key stretching is a
technique that can be used

165
00:07:11,880 --> 00:07:13,200
to strengthen a weak key.

166
00:07:13,200 --> 00:07:15,780
So maybe we had a 56 bit key.

167
00:07:15,780 --> 00:07:18,930
We can strengthen a weak
key into a stronger key.

168
00:07:18,930 --> 00:07:21,813
We often use that to protect
against brute force attacks.

169
00:07:23,280 --> 00:07:25,440
When you hear the term symmetric key,

170
00:07:25,440 --> 00:07:28,500
we mean one key, a single key.

171
00:07:28,500 --> 00:07:30,300
Sometimes it'll be referred
to as symmetric key.

172
00:07:30,300 --> 00:07:32,160
Sometimes it'll be referred
to as a secret key.

173
00:07:32,160 --> 00:07:34,320
Sometimes it'll be referred
to as a shared key.

174
00:07:34,320 --> 00:07:36,930
Sometimes it'll be refer
to as a single key.

175
00:07:36,930 --> 00:07:38,610
All of those mean the same thing.

176
00:07:38,610 --> 00:07:41,100
And what it means is
that we use the same key

177
00:07:41,100 --> 00:07:43,920
to encrypt as we do to decrypt.

178
00:07:43,920 --> 00:07:45,090
Think about the key that you use

179
00:07:45,090 --> 00:07:47,190
to get into your house or your apartment.

180
00:07:47,190 --> 00:07:49,050
You use the same key to unlock your door

181
00:07:49,050 --> 00:07:50,700
as you do to lock your door.

182
00:07:50,700 --> 00:07:53,640
Think about the key that
you use to start your car.

183
00:07:53,640 --> 00:07:54,510
Whether it's push button

184
00:07:54,510 --> 00:07:56,580
or you actually still turn the key,

185
00:07:56,580 --> 00:07:58,800
You use the same key to turn your car on

186
00:07:58,800 --> 00:08:01,503
as you do to turn it
off, that's symmetric.

187
00:08:02,730 --> 00:08:05,190
Asymmetric says that we
need to use two keys.

188
00:08:05,190 --> 00:08:07,710
They're gonna be mathematically related.

189
00:08:07,710 --> 00:08:10,200
We use one for encryption
and one for decryption.

190
00:08:10,200 --> 00:08:12,030
Now, both of them can do either function.

191
00:08:12,030 --> 00:08:13,860
Both can encrypt or decrypt,

192
00:08:13,860 --> 00:08:17,313
but you always have to use
'em in a pair configuration.

193
00:08:20,310 --> 00:08:23,400
Now we wanna make sure
that we secure our key.

194
00:08:23,400 --> 00:08:24,780
If we have just one key,

195
00:08:24,780 --> 00:08:27,150
so a symmetric key, a
single key, a shared key,

196
00:08:27,150 --> 00:08:28,980
even called a session key sometimes,

197
00:08:28,980 --> 00:08:30,150
we always wanna make sure that

198
00:08:30,150 --> 00:08:32,340
we're really keeping it secret.

199
00:08:32,340 --> 00:08:35,430
In a key pair, we're
going to have asymmetric.

200
00:08:35,430 --> 00:08:37,860
We're going to have one key
that is publicly distributed

201
00:08:37,860 --> 00:08:41,220
and one that is private
and must be kept secret.

202
00:08:41,220 --> 00:08:44,220
So for our private key
and for our symmetric key,

203
00:08:44,220 --> 00:08:46,860
we need to look at ways to really ensure

204
00:08:46,860 --> 00:08:48,750
the secrecy of that key.

205
00:08:48,750 --> 00:08:50,160
And there are a couple
of different options.

206
00:08:50,160 --> 00:08:52,500
There's a TPM, a trusted platform module.

207
00:08:52,500 --> 00:08:53,940
There's a secure enclave.

208
00:08:53,940 --> 00:08:56,970
There's an HSM that stands
for hardware security module,

209
00:08:56,970 --> 00:08:58,820
and there's the option of key escrow.

210
00:08:59,940 --> 00:09:01,860
A TPM is a hardware chip

211
00:09:01,860 --> 00:09:04,050
used for storing cryptographic keys

212
00:09:04,050 --> 00:09:05,613
and related information.

213
00:09:06,510 --> 00:09:10,830
A secure enclave is a separate
processor and microkernel

214
00:09:10,830 --> 00:09:13,260
that's used specifically
for storing and processing

215
00:09:13,260 --> 00:09:16,590
cryptographic keys and related information

216
00:09:16,590 --> 00:09:18,810
in mobile devices.

217
00:09:18,810 --> 00:09:22,200
An HSM is a hardened
tamper-resistant hardware device

218
00:09:22,200 --> 00:09:25,560
that we can use to
secure cryptographic keys

219
00:09:25,560 --> 00:09:27,360
and, again, related information.

220
00:09:27,360 --> 00:09:30,540
And key escrow is just
a safe keeping mechanism

221
00:09:30,540 --> 00:09:32,880
for storing and obtaining copies of keys

222
00:09:32,880 --> 00:09:35,700
that are needed to decrypt encrypted data

223
00:09:35,700 --> 00:09:39,210
under certain conditions
or certain circumstances,

224
00:09:39,210 --> 00:09:42,630
so you may give your attorney
right a copy of the key,

225
00:09:42,630 --> 00:09:46,953
and that key can only be used
in certain circumstances.

226
00:09:50,880 --> 00:09:52,950
Now, the strength of the crypto system

227
00:09:52,950 --> 00:09:55,710
is gonna be a combination
of a lot of factors.

228
00:09:55,710 --> 00:09:56,940
The algorithm, we'll be talking about

229
00:09:56,940 --> 00:09:58,650
lots of different algorithms shortly.

230
00:09:58,650 --> 00:10:00,480
The algorithmic process,

231
00:10:00,480 --> 00:10:02,220
the length of the key,

232
00:10:02,220 --> 00:10:03,990
and the secrecy of the key.

233
00:10:03,990 --> 00:10:06,300
And if any one element is weak,

234
00:10:06,300 --> 00:10:09,363
well, the crypto system can
potentially be compromised.

235
00:10:11,520 --> 00:10:13,200
Now there are two terms
you're going to hear

236
00:10:13,200 --> 00:10:15,600
in relation to cryptographic strength.

237
00:10:15,600 --> 00:10:18,870
One is deprecated and the other is broken.

238
00:10:18,870 --> 00:10:21,660
Deprecated means that
the use of the algorithm,

239
00:10:21,660 --> 00:10:25,020
or the key length, or
the process is allowed,

240
00:10:25,020 --> 00:10:27,150
but the user must accept some risk

241
00:10:27,150 --> 00:10:29,460
due to inherent weaknesses.

242
00:10:29,460 --> 00:10:33,030
So you can use it, but you
need to know it's weak,

243
00:10:33,030 --> 00:10:36,960
and an example is the 3DES algorithm,

244
00:10:36,960 --> 00:10:38,970
and we'll talk more about that shortly.

245
00:10:38,970 --> 00:10:42,390
Broken means either the
key and/or the key length

246
00:10:42,390 --> 00:10:45,720
or the processes behind it is exploitable,

247
00:10:45,720 --> 00:10:48,240
which means it's not
gonna secure you anymore.

248
00:10:48,240 --> 00:10:50,070
So deprecated is weak.

249
00:10:50,070 --> 00:10:51,633
Broken is exploitable.

250
00:10:52,710 --> 00:10:54,030
That's the end of our primer.

251
00:10:54,030 --> 00:10:56,580
That's gonna bring us to
a three-second challenge.

252
00:10:56,580 --> 00:10:59,100
Then we'll go off into
lessons about encryption,

253
00:10:59,100 --> 00:11:01,800
and hashing, and digital signatures,

254
00:11:01,800 --> 00:11:06,800
and digital certificates as
well as emerging cryptography.

255
00:11:08,220 --> 00:11:09,990
So three second challenge, are you ready?

256
00:11:09,990 --> 00:11:11,850
Five challenge questions,
three seconds each.

257
00:11:11,850 --> 00:11:13,140
I know you can do these.

258
00:11:13,140 --> 00:11:15,240
One, two, three. Let's start.

259
00:11:15,240 --> 00:11:18,570
A mathematically complex
modern cipher is a...

260
00:11:18,570 --> 00:11:20,160
One, two, three.

261
00:11:20,160 --> 00:11:21,160
That's an algorithm.

262
00:11:22,380 --> 00:11:24,573
Secret value that's
used with an algorithm.

263
00:11:25,590 --> 00:11:28,320
One, two, three.

264
00:11:28,320 --> 00:11:29,490
That's gonna be a key.

265
00:11:29,490 --> 00:11:31,680
And if you said crypto
variable, well, you're very cool

266
00:11:31,680 --> 00:11:33,430
'cause it's also a crypto variable.

267
00:11:34,620 --> 00:11:35,790
All right, number three.

268
00:11:35,790 --> 00:11:39,870
The term used to describe a
weak cryptographic element.

269
00:11:39,870 --> 00:11:43,440
One, two, three.

270
00:11:43,440 --> 00:11:44,970
That's gonna be deprecated number.

271
00:11:44,970 --> 00:11:46,920
Remember deprecated if it's weak.

272
00:11:46,920 --> 00:11:48,573
Broken if it's been exploited.

273
00:11:49,860 --> 00:11:53,970
Number four, a separate
processor and microkernel

274
00:11:53,970 --> 00:11:57,390
used for storing and
processing cryptographic keys

275
00:11:57,390 --> 00:11:59,223
in mobile devices.

276
00:12:00,060 --> 00:12:02,190
It's important in mobile devices.

277
00:12:02,190 --> 00:12:03,543
One, two, three.

278
00:12:04,950 --> 00:12:06,900
That's gonna be a secure enclave.

279
00:12:06,900 --> 00:12:09,180
And lastly, number five.

280
00:12:09,180 --> 00:12:12,300
The number of possible key combinations.

281
00:12:12,300 --> 00:12:14,670
So I'm not asking you to give me a number.

282
00:12:14,670 --> 00:12:16,650
I'm asking you to tell me
what is that referred to,

283
00:12:16,650 --> 00:12:19,380
the number of possible key combinations.

284
00:12:19,380 --> 00:12:20,853
One, two, three.

285
00:12:22,080 --> 00:12:23,380
And that's your key space.

286
00:12:24,540 --> 00:12:26,160
All right, let's do our first

287
00:12:26,160 --> 00:12:28,470
cryptographic security in action.

288
00:12:28,470 --> 00:12:30,420
This is about key security.

289
00:12:30,420 --> 00:12:33,330
Your municipal employer,
Anytown Revenue Service,

290
00:12:33,330 --> 00:12:36,600
wants to encrypt taxpayer data at rest.

291
00:12:36,600 --> 00:12:37,890
Now, it's important that they adhere

292
00:12:37,890 --> 00:12:38,910
to government standards,

293
00:12:38,910 --> 00:12:41,610
so they're planning on
using 3DES algorithm

294
00:12:41,610 --> 00:12:43,470
for symmetric encryption.

295
00:12:43,470 --> 00:12:44,880
Now, I get that we haven't talked about

296
00:12:44,880 --> 00:12:45,840
symmetric encryption yet.

297
00:12:45,840 --> 00:12:47,670
We haven't talked about 3DES,

298
00:12:47,670 --> 00:12:49,380
but just kinda go with it.

299
00:12:49,380 --> 00:12:52,200
Now, they wanna make sure
that internal employees

300
00:12:52,200 --> 00:12:54,810
have easy access to the data,

301
00:12:54,810 --> 00:12:57,480
so they plan to publish the key

302
00:12:57,480 --> 00:12:59,430
on their intranet.

303
00:12:59,430 --> 00:13:01,530
Now, symmetric, what does that mean?

304
00:13:01,530 --> 00:13:03,390
Symmetric means there's one key,

305
00:13:03,390 --> 00:13:07,110
shared key, single key,
secret key, session key,

306
00:13:07,110 --> 00:13:09,360
one key to encrypt and decrypt.

307
00:13:09,360 --> 00:13:10,890
So here's the important thing.

308
00:13:10,890 --> 00:13:12,990
They wanna make sure
the internal employees

309
00:13:12,990 --> 00:13:14,460
have easy access to data,

310
00:13:14,460 --> 00:13:18,750
so they plan to publish
the key on their intranet.

311
00:13:18,750 --> 00:13:22,413
So do you have any concerns
about this approach?

312
00:13:23,460 --> 00:13:25,560
Go ahead and put me on
pause, jot down some notes.

313
00:13:25,560 --> 00:13:28,953
Let me know if you have any
concerns about their approach.

314
00:13:31,410 --> 00:13:32,463
Well, I hope you do.

315
00:13:33,600 --> 00:13:35,370
The strength of the crypto system

316
00:13:35,370 --> 00:13:38,760
is a combination of the algorithm,
the algorithmic process,

317
00:13:38,760 --> 00:13:41,910
the length of the key, and
the secrecy of the key.

318
00:13:41,910 --> 00:13:45,240
Now, we weren't really
asked to comment here about

319
00:13:45,240 --> 00:13:47,130
whether they're using
symmetric or asymmetric,

320
00:13:47,130 --> 00:13:49,560
or the fact they're gonna
use a 3DES algorithm.

321
00:13:49,560 --> 00:13:51,750
What we really are commenting on is

322
00:13:51,750 --> 00:13:54,423
publishing the key on their intranet.

323
00:13:56,040 --> 00:13:58,170
But I will tell you
that 3DES is deprecated

324
00:13:58,170 --> 00:13:59,070
and shouldn't be used.

325
00:13:59,070 --> 00:14:01,620
Again, you wouldn't have
necessarily known that yet.

326
00:14:01,620 --> 00:14:04,800
The AES has replaced 3DES as
the US government standard.

327
00:14:04,800 --> 00:14:07,553
Again, not something you
necessarily would've known yet.

328
00:14:08,940 --> 00:14:10,710
But here's what you should have known,

329
00:14:10,710 --> 00:14:13,020
that the security of symmetric encryption

330
00:14:13,020 --> 00:14:15,150
depends upon the secrecy

331
00:14:15,150 --> 00:14:18,480
of the single shared
crypto variable or key.

332
00:14:18,480 --> 00:14:22,680
That key, 100%, definitely,
definitely definitely

333
00:14:22,680 --> 00:14:26,280
should not be published on their intranet.

334
00:14:26,280 --> 00:14:27,960
And knowing that, my friends,

335
00:14:27,960 --> 00:14:30,453
is absolutely security in action.

336
00:14:32,250 --> 00:14:33,360
All right, there you go.

337
00:14:33,360 --> 00:14:35,070
That's your word cloud.
You know what to do.

338
00:14:35,070 --> 00:14:37,290
I don't want you moving
on to the next lesson

339
00:14:37,290 --> 00:14:40,200
until you're comfortable
with all these terms

340
00:14:40,200 --> 00:14:42,900
and you're confident that
you can explain them.

341
00:14:42,900 --> 00:14:45,117
But when you're ready, head
on over to the next lesson,

342
00:14:45,117 --> 00:14:47,040
and we're gonna be
talking about encryption.

343
00:14:47,040 --> 00:14:47,873
See you there.
