"Thanks, But No Thanks: Current Cryptographic Standards Are Sufficient for Software": http://csrc.nist.gov/groups/ST/lwc-workshop2015/presentations/session4-shumow.pdf …. This is regarding IoT devices.
@frgx Dependong on the type of device, updatable firmware is relatively expensive to implement, even if you ignore the usability issues.
-
-
@BRIAN_____ replace "updatable firmware" with "strong crypto" ;) -
@frgx I think the strong crypto part is much easier to solve, for a larger class of devices, than updates. The hard crypto part is the PRNG. -
@BRIAN_____@frgx Can you have strong crypto without updates? -
-
@BRIAN_____@jyasskin absolutely; just saying that I would prioritize reliable, fast patching over algorithmic hardening -
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.