ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Thirty years on, cryptography still too hard to use?

Joris Evers CNET News.com

Published: 30 Oct 2006 17:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

US government controls held back cryptography in the past, but today, it's usability that blocks adoption, a panel of experts said on Thursday.

At an event in Mountain View, California, celebrating 30 years of public key cryptography, several top minds in the field gathered for a trip down memory lane. Over the years, public key cryptography has grown from an idea in a paper published by Whitfield Diffie and Martin Hellman, both present at the event, to technology used in everyday transactions on the web.

The US government was a major obstacle in advancing cryptography until it lifted export controls in 1996, a panel of experts said. Much of the discussion Thursday evening covered that topic, with Brian Snow, a retired technical director at the National Security Agency, offering some insight into what happened at the government in the 20 years before that.

"This, for us, was a weapon," Snow said. "And this was possible free release of weapons we needed to defend the nation to other nations who could be opponents at times."

As cryptography grew out of the research stage and into actual products, companies such as RSA Security had a tough time establishing themselves. In 1986, Jim Bidzos, then chief executive of RSA, at times, felt his business wouldn't go anywhere.

"There was this big monster in Maryland that I discovered that we had to deal with," Bidzos said. "We found ourselves competing with NSA, especially in the '90s."

One of RSA's first customers was Ray Ozzie. Today, he's chief software architect at Microsoft, but back in 1986, Ozzie was looking to secure what would become Lotus Notes. Security was necessary to prevent eavesdropping on communications, as Ozzie admitted he himself had done in the past.

"I was a student systems programmer, and we used to have lots of fun looking inside of people's email and private discussions," he said, talking about his days in the late 1970s and early 1980s at the University of Illinois, when he worked on Plato, a computer-based education system.

But when it came time to get an export licence for Lotus Notes, Ozzie ran into the US government's restrictions. "I had no clue," Ozzie said. "Initially, we had wanted to use hefty keys... We had spent years working on it, and after the third meeting (with the government), I thought we were dead."

But that's all history. The web hit in 1994, erasing borders and giving rise to the need to secure electronic commerce. In 1996, the government eased export controls, clearing most regulatory obstacles for widespread adoption of cryptography.

"The one thing I fault the (NSA) for is that they were not willing to be open-minded in the discussion," Snow said. "There was a very valid case to be made on the other side."

The government has even made an about-face on encryption. These days, many regulations such as those laid down by HIPAA and the Sarbanes-Oxley Act require encryption, noted Dan Boneh, an associate professor of computer science at Stanford University and co-founder of Voltage Security.

"There has been a complete flip recognising that encryption is here to help us," Boneh said.

Yet cryptography hasn't become as commonly used as some might have hoped, the panel noted. Web transactions might be encrypted, but a lot of data and communications still are not.

The issue, Snow said, is products. "The remaining issue that is big today on the plate is lack of quality in the products," he said, adding that security products are poorly designed and often not in a secure way.

Other panelists agreed. "I will fix it all," Ozzie said. He said he had built security into Notes and in Groove, a later venture. At Microsoft, he plans to design it into products as well, keeping in mind compliance issues and the realities of enterprise systems, he said.

"In the early years, we as an industry could blame the system for controlling the pace of innovation because the government was throwing up roadblocks," Ozzie said. "At this moment in time, it's laziness on the part of the industry in terms of not embracing architecture and the importance of human interface in design of secure systems."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
459 out of 619 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Lotus Notes / Domino Developer - Global Client - Urgent

Huxley Associates reputable client based in Paddington, Central London have the requirement for 2x Lotus Notes Developers to start immediately for ...

Lotus Notes Support

Huxley Associates have a requirement for a Lotus Notes support specialist to join a client in Milton Keynes. On a day to day basis you will be: - ...

UNIX Redhat & Windows Senior Administrator 35k Warrington

Skills required include: - Desirable skills include experience of Red Hat Linux, Windows Server 2003 and exposure to ISO and ITIL - Knowledge of ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec