The Cost of Stunt Cryptography

by Peter Gutmann | - 10:30am

Cryptographers like presenting new and novel attacks, the more exotic the better, even more so if you can come up with a clever name and web site to accompany it. However there is a real cost to these cryptographic stunts in that they invariably trigger a governance process in which the maintainers of the affected software then need to respond to an often nonexistent threat, something that can take months of work and cost tens of thousands of dollars. This talk looks at the overlooked aspect of stunt cryptography, the cost to developers of having to respond to the stunts.

About Peter Gutmann

Peter Gutmann is a researcher in the Department of Computer Science at the University of Auckland working on design and analysis of cryptographic security architectures, security usability, and embedded systems security. He helped write the popular PGP encryption package, has authored a number of papers and RFC’s on security and encryption including serving as the final editor of the world’s longest-running security RFC, RFC 8894, and is the author of the open source cryptlib security toolkit, the book “Cryptographic Security Architecture: Design and Verification”, and an upcoming book “Engineering Security”. In his spare time he pokes holes in whatever security systems and mechanisms catch his attention and grumbles about the lack of consideration of human factors in designing security systems.

Other talks