At RSA Conference, Computer Security Done Right and Wrong

Source 
Author 
Coverage Type 

The annual RSA security conference in San Francisco (CA) is one of the largest gatherings of computer security professionals and companies in the world. It is also an opportunity for complaining and perhaps just a bit of navel gazing. If 2013 was the “Year of the Breach” and 2014 was the “Year of the Mega-Breach,” 2015 may be the year that we run out of adjectives and start demanding real accountability from security vendors. “The largest enterprises with the most sophisticated, ‘next-generation’ security tools were not able to stop miscreants from making off with millions of dollars, personal information, and sensitive secrets and damaging reputations,” Amit Yoran, the president of RSA, said in his keynote speech. Additionally, the National Security Agency can forget about that encryption “front door.”

In a talk earlier in April at Princeton University, Admiral Michael S. Rogers, director of the NSA, suggested that the intelligence community and Silicon Valley might reach some sort of technical compromise on the question of whether intelligence agencies and law enforcement would still have access to the data that Facebook, Apple, Google and others recently resolved to encrypt. Adm. Rogers said he was not looking for a “back door” but a “front door” with “multiple locks -- big locks.” Government officials are toying with the idea of key escrow, in which the government might hold onto part of an encryption key, and a company could hold onto the other. But security experts at the RSA conference say that, in reality, no such secure mechanism exists. “Technically speaking, there’s a serious misunderstanding about key escrow,” Ron Rivest, one of the inventors of the RSA encryption algorithm said during a cryptography panel. “The head of the NSA is misusing this idea.” Others agreed. “There is no sane argument for weakening encryption,” Yoran said. “Period."


At RSA Conference, Computer Security Done Right and Wrong