Tan115 commited on
Commit
666213d
·
verified ·
1 Parent(s): 94eae43

Add files using upload-large-folder tool

Browse files
This view is limited to 50 files because it contains too many changes.   See raw diff
Files changed (50) hide show
  1. .gitattributes +31 -0
  2. 04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 +3 -0
  3. 05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 +3 -0
  4. 05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 +3 -0
  5. 05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 +3 -0
  6. 05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 +3 -0
  7. 05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 +3 -0
  8. 05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 +3 -0
  9. 05 - Vulnerabilities/007 XSS OB 2.3.mp4 +3 -0
  10. 05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 +3 -0
  11. 05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 +3 -0
  12. 05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 +3 -0
  13. 05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 +3 -0
  14. 05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 +3 -0
  15. 05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 +3 -0
  16. 05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 +3 -0
  17. 05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 +3 -0
  18. 06 - Signs of Attacks/001 Malware OB 2.4.mp4 +3 -0
  19. 06 - Signs of Attacks/002 Viruses OB 2.4.mp4 +3 -0
  20. 06 - Signs of Attacks/003 Worms OB 2.4.mp4 +3 -0
  21. 06 - Signs of Attacks/004 Trojans OB 2.4.mp4 +3 -0
  22. 06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 +3 -0
  23. 06 - Signs of Attacks/006 Spyware OB 2.4.mp4 +3 -0
  24. 06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 +3 -0
  25. 06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 +3 -0
  26. 06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 +3 -0
  27. 06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 +3 -0
  28. 06 - Signs of Attacks/011 DDOS OB 2.4.mp4 +3 -0
  29. 06 - Signs of Attacks/012 DNS OB 2.4.mp4 +3 -0
  30. 06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 +3 -0
  31. 06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 +3 -0
  32. 06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 +3 -0
  33. 07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt +852 -0
  34. 07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt +268 -0
  35. 07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt +488 -0
  36. 07 - Cryptography/011 Hashing OB 1.4_en.srt +1600 -0
  37. 07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt +240 -0
  38. 07 - Cryptography/013 Digital Signatures OB 1.4_en.srt +636 -0
  39. 07 - Cryptography/014 Intro to PKI OB 1.4_en.srt +124 -0
  40. 07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt +1176 -0
  41. 07 - Cryptography/017 PKI Process OB 1.4_en.srt +664 -0
  42. 07 - Cryptography/018 Certificates OB 1.4_en.srt +824 -0
  43. 07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt +220 -0
  44. 07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt +372 -0
  45. 07 - Cryptography/021 Steganography OB 1.4_en.srt +392 -0
  46. 07 - Cryptography/022 Blockchain OB 1.4_en.srt +476 -0
  47. 07 - Cryptography/023 Salting OB 1.4_en.srt +352 -0
  48. 07 - Cryptography/024 TPM OB 1.4_en.srt +284 -0
  49. 07 - Cryptography/025 Secure Enclave OB 1.4_en.srt +124 -0
  50. 07 - Cryptography/026 Obfuscation OB 1.4_en.srt +252 -0
.gitattributes CHANGED
@@ -65,3 +65,34 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
65
  04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
66
  04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
67
  04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
65
  04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
66
  04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
67
  04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
68
+ 05[[:space:]]-[[:space:]]Vulnerabilities/001[[:space:]]Vulnerabilities[[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
69
+ 04[[:space:]]-[[:space:]]Threats/009[[:space:]]Threat[[:space:]]Vectors[[:space:]]and[[:space:]]Attack[[:space:]]Surfaces[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
70
+ 05[[:space:]]-[[:space:]]Vulnerabilities/003[[:space:]]Race[[:space:]]Conditions[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
71
+ 05[[:space:]]-[[:space:]]Vulnerabilities/004[[:space:]]Malicious[[:space:]]Updates[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
72
+ 05[[:space:]]-[[:space:]]Vulnerabilities/002[[:space:]]Memory[[:space:]]injection[[:space:]]and[[:space:]]buffer[[:space:]]overflows[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
73
+ 05[[:space:]]-[[:space:]]Vulnerabilities/005[[:space:]]OS-Based[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
74
+ 05[[:space:]]-[[:space:]]Vulnerabilities/007[[:space:]]XSS[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
75
+ 05[[:space:]]-[[:space:]]Vulnerabilities/008[[:space:]]Hardware[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
76
+ 05[[:space:]]-[[:space:]]Vulnerabilities/006[[:space:]]SQL[[:space:]]Injections[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
77
+ 05[[:space:]]-[[:space:]]Vulnerabilities/009[[:space:]]VM[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
78
+ 05[[:space:]]-[[:space:]]Vulnerabilities/011[[:space:]]Supply[[:space:]]Chain[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
79
+ 05[[:space:]]-[[:space:]]Vulnerabilities/010[[:space:]]Cloud-specific[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
80
+ 05[[:space:]]-[[:space:]]Vulnerabilities/012[[:space:]]Cryptographic[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
81
+ 05[[:space:]]-[[:space:]]Vulnerabilities/013[[:space:]]Misconfiguration[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
82
+ 05[[:space:]]-[[:space:]]Vulnerabilities/014[[:space:]]Mobile[[:space:]]Device[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
83
+ 05[[:space:]]-[[:space:]]Vulnerabilities/015[[:space:]]Zero-day[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
84
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/001[[:space:]]Malware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
85
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/002[[:space:]]Viruses[[:space:]][[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
86
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/004[[:space:]]Trojans[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
87
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/003[[:space:]]Worms[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
88
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/006[[:space:]]Spyware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
89
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/007[[:space:]]Rootkit[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
90
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/008[[:space:]]Logic[[:space:]]Bomb[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
91
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/005[[:space:]]Ransomware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
92
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/010[[:space:]]Bloatware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
93
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/009[[:space:]]Keyloggers[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
94
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/012[[:space:]]DNS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
95
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/013[[:space:]]Onpath[[:space:]]Attack[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
96
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
97
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
98
+ 06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:0ea8bb280b7aa00ee6e5ff91314a79037663623e7fc0b5bc46c28628bd17c02d
3
+ size 358178371
05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:cb6b5599cca6eea9c2736821187b2aca950a91ed895c076d4afa1a635fda33d4
3
+ size 51453967
05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:f68268c8a6df35545a34b6537ff1ae3457a4a8a1f3413909a541023c7c3533fe
3
+ size 303240221
05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:827629d12a9db8054ddd7bb753593d6cd2cd3395f43a6309f817875330c90f57
3
+ size 218816868
05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:224434b0ef6bdf7a0421decbf0ac02826ca27f1b0b631d052af6e86d3d65205a
3
+ size 69037281
05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:58c34142c72f36bd099bc2e9175544ef81586d217f9782088d54545c5f48c0ec
3
+ size 226457460
05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:eac89091ca6406c03551377c8688fd4f52d61ea836f83a9a88fca22983059eb0
3
+ size 408025612
05 - Vulnerabilities/007 XSS OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:1ebc247a98f8eb09c18681b79469de174d97f5b3bde93a4d44d1f383a772ef17
3
+ size 135683436
05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7300861fccd624dcc80384ffec805620c4605fa31cd3435e4fca9f74433ce30d
3
+ size 175563789
05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:7ac9de70b4d06911c5960aa76d9d9e178d5fd0d57d42cf7c553f0df071456adc
3
+ size 89576988
05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:22e716b22c428835c49530cf3483a6b38b841fbc70b803e0055513dbb7c020f2
3
+ size 316842710
05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:09f04bddcaebb5f48817b818fe3db8c8df91a70cc8e1cf628d74965009d87964
3
+ size 269551046
05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:0d9d15aa0b12a658e8ccce53dd290c49c87091e21c64ecff4f22e24b404ceba7
3
+ size 198706946
05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:85c11b70fa06e0769ea994ff665d1bf07a2b0c03cdd67298bf1f2eb45b97c5fa
3
+ size 176934829
05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:0fbe44a5da82866917e877f6218b89d8453d1fcfae4552f30b87cc3935a1bfde
3
+ size 428914675
05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:12993189b8460e9f3acfed58036f5a19a4b20ef26605359d2fa858e4b3dd0009
3
+ size 180828460
06 - Signs of Attacks/001 Malware OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b81cb76d342e2cf86c742e50cfcb7d13c031c85aa5ea688543554782e20aad07
3
+ size 35123665
06 - Signs of Attacks/002 Viruses OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:15d6f166dbb596a6b3bb9e2f6da2cbfed8b994740dfa98146fbaf91769413057
3
+ size 314530848
06 - Signs of Attacks/003 Worms OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:3e83018efbed549c09b383906c59a3c4460f03cff47704283c4c7888340fe6e9
3
+ size 216076980
06 - Signs of Attacks/004 Trojans OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ebe35a406da737d6f80d67253e884141c0f52aee970099aa8425df24b1e6396a
3
+ size 156627975
06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:cba44cc2f789d7f0f71483eae60d97a517b718f29d2817e5815b1a000bf425bd
3
+ size 249594928
06 - Signs of Attacks/006 Spyware OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:fa3bb793eb84c4f30d6036707ff90ef34fd5c478c7159cef46d5c268b09165df
3
+ size 142438065
06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:a587afe5ed336a341348c0f88fedbf5a5f4d27cf8cfafb8899c085755d158695
3
+ size 154446570
06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:923d96eca9619dc8fd2982cdf24f4f9397626c36f5dd66cbc3386f2b91bbbc52
3
+ size 101035815
06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:2679df59b2c32e13cc3300549d25a8dc8a0d97f17800d367c74bd4193928ebc9
3
+ size 237412212
06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:fac8a4f1ace9423b2a2c0dd5461d0e98c56c5ff76f77b0b051af18f59ee0fe9c
3
+ size 74555519
06 - Signs of Attacks/011 DDOS OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:69dcc08a90ce0d4cf044b01258d8e48b84c7e34b84bac088d57543d5579db03e
3
+ size 613421399
06 - Signs of Attacks/012 DNS OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:b612b9f273589d5f6721a35735ea5ed9fd8379f95084693b1b835e872681a8dc
3
+ size 483439518
06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:68088df41f07e4224ed283a402705a7a282be595a3658a10edb77010f1085c5c
3
+ size 285525484
06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:57f8c7337a266a61625b6f6b8cc1391a578baede810e98a3899df66a98ab58df
3
+ size 192202206
06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:521b6ee434ae5b7389c51416249182d8b4b6a8aead0235b28082f271380afcf2
3
+ size 176957870
07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt ADDED
@@ -0,0 +1,852 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:00,000
3
+ Okay.
4
+
5
+ 2
6
+ 00:00:00,000 --> 00:00:02,000
7
+ So we just covered symmetric encryption.
8
+
9
+ 3
10
+ 00:00:02,000 --> 00:00:08,000
11
+ And if you remember correctly the key to choosing to encrypt is the same key that's used to decrypt.
12
+
13
+ 4
14
+ 00:00:08,000 --> 00:00:13,000
15
+ When in this video I want to take a deep dive into the concepts of asymmetric cryptography.
16
+
17
+ 5
18
+ 00:00:13,000 --> 00:00:19,000
19
+ Now I briefly mentioned that asymmetric and symmetric combines together in a hybrid cryptography system
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:21,000
23
+ to actually transport secure data.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:23,000
27
+ So you actually.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:28,000
31
+ Can't really do secure communication today technically without asymmetric.
32
+
33
+ 9
34
+ 00:00:28,000 --> 00:00:30,000
35
+ So let's get a deep dive into it.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:32,000
39
+ But what exactly is it you see?
40
+
41
+ 11
42
+ 00:00:32,000 --> 00:00:33,000
43
+ Asymmetric encryption.
44
+
45
+ 12
46
+ 00:00:33,000 --> 00:00:34,000
47
+ So the word symmetric means the same.
48
+
49
+ 13
50
+ 00:00:34,000 --> 00:00:36,000
51
+ Asymmetric is going to mean different.
52
+
53
+ 14
54
+ 00:00:37,000 --> 00:00:38,000
55
+ Is known.
56
+
57
+ 15
58
+ 00:00:38,000 --> 00:00:43,000
59
+ First of all I want to mention is something we call public key cryptography.
60
+
61
+ 16
62
+ 00:00:43,000 --> 00:00:43,000
63
+ All right.
64
+
65
+ 17
66
+ 00:00:43,000 --> 00:00:45,000
67
+ Public key cryptography.
68
+
69
+ 18
70
+ 00:00:45,000 --> 00:00:50,000
71
+ Now, keep in mind, if anybody ever says you read in any book, they say something like secret key
72
+
73
+ 19
74
+ 00:00:50,000 --> 00:00:53,000
75
+ cryptography or private key cryptography.
76
+
77
+ 20
78
+ 00:00:53,000 --> 00:00:58,000
79
+ That is symmetric public key cryptography is asymmetric.
80
+
81
+ 21
82
+ 00:00:59,000 --> 00:01:06,000
83
+ This is a cryptographic system that uses pairs of keys, a public key which is given out widely, and
84
+
85
+ 22
86
+ 00:01:06,000 --> 00:01:08,000
87
+ a private key which is only known to the users.
88
+
89
+ 23
90
+ 00:01:08,000 --> 00:01:13,000
91
+ So everybody has two keys, a public key and a private key.
92
+
93
+ 24
94
+ 00:01:13,000 --> 00:01:17,000
95
+ The public key encryption decrypts and it's given with anyone.
96
+
97
+ 25
98
+ 00:01:17,000 --> 00:01:20,000
99
+ The private key can also encrypt and decrypt, and it's kept with the owner.
100
+
101
+ 26
102
+ 00:01:20,000 --> 00:01:21,000
103
+ No one gets it.
104
+
105
+ 27
106
+ 00:01:21,000 --> 00:01:26,000
107
+ Remember that everybody in the crypto system has two keys.
108
+
109
+ 28
110
+ 00:01:26,000 --> 00:01:32,000
111
+ So for example, let's say I got me Mary and Bob.
112
+
113
+ 29
114
+ 00:01:32,000 --> 00:01:33,000
115
+ Well easy.
116
+
117
+ 30
118
+ 00:01:33,000 --> 00:01:35,000
119
+ I'm going to have a public private key.
120
+
121
+ 31
122
+ 00:01:35,000 --> 00:01:37,000
123
+ Mary is going to have a public private key.
124
+
125
+ 32
126
+ 00:01:37,000 --> 00:01:42,000
127
+ And Bob is going to have and Bob is going to have a public everybody has a public private key.
128
+
129
+ 33
130
+ 00:01:42,000 --> 00:01:46,000
131
+ The way the encryption process works is different than symmetric and symmetric.
132
+
133
+ 34
134
+ 00:01:46,000 --> 00:01:50,000
135
+ I generate the data, I generate the key I encrypted, give them the data, give them the key.
136
+
137
+ 35
138
+ 00:01:50,000 --> 00:01:51,000
139
+ They use the key to decrypt the data.
140
+
141
+ 36
142
+ 00:01:51,000 --> 00:01:53,000
143
+ This is going to work different.
144
+
145
+ 37
146
+ 00:01:53,000 --> 00:01:58,000
147
+ And for that I want to I want to draw a little diagram here to get you guys an understanding of the
148
+
149
+ 38
150
+ 00:01:58,000 --> 00:02:00,000
151
+ encryption and decryption process.
152
+
153
+ 39
154
+ 00:02:02,000 --> 00:02:05,000
155
+ So let's go in here and let me just draw.
156
+
157
+ 40
158
+ 00:02:05,000 --> 00:02:07,000
159
+ Let's say you have two users on a network.
160
+
161
+ 41
162
+ 00:02:07,000 --> 00:02:11,000
163
+ There's Andrew and there's Mary.
164
+
165
+ 42
166
+ 00:02:11,000 --> 00:02:18,000
167
+ Now the way the encryption process works here is that I'm going to have a public private Mary also has
168
+
169
+ 43
170
+ 00:02:18,000 --> 00:02:20,000
171
+ a public private key.
172
+
173
+ 44
174
+ 00:02:20,000 --> 00:02:24,000
175
+ But let's say I want to transfer data to Mary.
176
+
177
+ 45
178
+ 00:02:24,000 --> 00:02:26,000
179
+ I want to give Mary the answers to the exam.
180
+
181
+ 46
182
+ 00:02:26,000 --> 00:02:27,000
183
+ So.
184
+
185
+ 47
186
+ 00:02:28,000 --> 00:02:29,000
187
+ How am I going to do it?
188
+
189
+ 48
190
+ 00:02:29,000 --> 00:02:31,000
191
+ Well, I have data.
192
+
193
+ 49
194
+ 00:02:32,000 --> 00:02:34,000
195
+ That I want to transfer to Mary.
196
+
197
+ 50
198
+ 00:02:34,000 --> 00:02:38,000
199
+ What I'm going to do and says, hey, Mary, you you're free.
200
+
201
+ 51
202
+ 00:02:38,000 --> 00:02:41,000
203
+ Okay, Mary, can you send me your public key?
204
+
205
+ 52
206
+ 00:02:41,000 --> 00:02:45,000
207
+ Mary sends me her public key, and I encrypt the data with the public key.
208
+
209
+ 53
210
+ 00:02:45,000 --> 00:02:47,000
211
+ And now I got cipher text.
212
+
213
+ 54
214
+ 00:02:47,000 --> 00:02:50,000
215
+ I send it to Mary, a cipher text.
216
+
217
+ 55
218
+ 00:02:50,000 --> 00:02:57,000
219
+ Mary then utilizes her private key to decrypt this data to get the plain text or the data.
220
+
221
+ 56
222
+ 00:02:58,000 --> 00:02:59,000
223
+ So.
224
+
225
+ 57
226
+ 00:03:01,000 --> 00:03:02,000
227
+ I put some lines here.
228
+
229
+ 58
230
+ 00:03:02,000 --> 00:03:07,000
231
+ So that's the decryption process encryption and decryption process.
232
+
233
+ 59
234
+ 00:03:07,000 --> 00:03:12,000
235
+ Now technically it doesn't actually work like this because we don't actually do this.
236
+
237
+ 60
238
+ 00:03:13,000 --> 00:03:15,000
239
+ Uh, we use it in a hybrid method, but I'm going to cover that later.
240
+
241
+ 61
242
+ 00:03:15,000 --> 00:03:17,000
243
+ But for now, just this is good enough.
244
+
245
+ 62
246
+ 00:03:18,000 --> 00:03:20,000
247
+ Now I want to point out a couple of things here.
248
+
249
+ 63
250
+ 00:03:20,000 --> 00:03:23,000
251
+ You notice that I never utilized any of my keys.
252
+
253
+ 64
254
+ 00:03:24,000 --> 00:03:26,000
255
+ I utilize the person that was receiving the data keys.
256
+
257
+ 65
258
+ 00:03:26,000 --> 00:03:28,000
259
+ I utilize their public key, right?
260
+
261
+ 66
262
+ 00:03:28,000 --> 00:03:29,000
263
+ Did you see that?
264
+
265
+ 67
266
+ 00:03:29,000 --> 00:03:30,000
267
+ Think about going to Amazon.
268
+
269
+ 68
270
+ 00:03:30,000 --> 00:03:33,000
271
+ When you go to Amazon, you don't have any keys, but Amazon does.
272
+
273
+ 69
274
+ 00:03:34,000 --> 00:03:36,000
275
+ Keep this in mind when I get to SSL.
276
+
277
+ 70
278
+ 00:03:36,000 --> 00:03:41,000
279
+ So this is a really important system because there's a couple of things here I want to point out.
280
+
281
+ 71
282
+ 00:03:41,000 --> 00:03:46,000
283
+ Notice the public key encrypted the data and a private key decrypted data.
284
+
285
+ 72
286
+ 00:03:46,000 --> 00:03:47,000
287
+ That's a concept you need to understand.
288
+
289
+ 73
290
+ 00:03:48,000 --> 00:03:52,000
291
+ So when one key encrypts, only the other key can decrypt it.
292
+
293
+ 74
294
+ 00:03:52,000 --> 00:03:56,000
295
+ So when a public key encrypts, only the corresponding private key can decrypt it.
296
+
297
+ 75
298
+ 00:03:56,000 --> 00:03:59,000
299
+ If the private key encrypts it and it does encrypt.
300
+
301
+ 76
302
+ 00:03:59,000 --> 00:04:03,000
303
+ For those of you that say no in a digital signature, a private key does decrypt.
304
+
305
+ 77
306
+ 00:04:03,000 --> 00:04:03,000
307
+ I'm sorry.
308
+
309
+ 78
310
+ 00:04:03,000 --> 00:04:04,000
311
+ Encrypt.
312
+
313
+ 79
314
+ 00:04:05,000 --> 00:04:07,000
315
+ If the private encrypt the public decrypts.
316
+
317
+ 80
318
+ 00:04:07,000 --> 00:04:13,000
319
+ Remember that when one key encrypts, only the corresponding other key can decrypt it.
320
+
321
+ 81
322
+ 00:04:13,000 --> 00:04:17,000
323
+ The public key cannot encrypt and decrypt at the same time.
324
+
325
+ 82
326
+ 00:04:17,000 --> 00:04:20,000
327
+ The private key cannot encrypt and decrypt at the same time.
328
+
329
+ 83
330
+ 00:04:20,000 --> 00:04:23,000
331
+ When one encrypts the other, one must decrypt.
332
+
333
+ 84
334
+ 00:04:23,000 --> 00:04:24,000
335
+ And that's what you see here.
336
+
337
+ 85
338
+ 00:04:24,000 --> 00:04:26,000
339
+ We take the data.
340
+
341
+ 86
342
+ 00:04:26,000 --> 00:04:29,000
343
+ We encrypt it with Mary's public key.
344
+
345
+ 87
346
+ 00:04:30,000 --> 00:04:34,000
347
+ She gets the ciphertext and she decrypts it with her private key to get the data.
348
+
349
+ 88
350
+ 00:04:34,000 --> 00:04:38,000
351
+ So that's something that you must understand here.
352
+
353
+ 89
354
+ 00:04:38,000 --> 00:04:38,000
355
+ Now.
356
+
357
+ 90
358
+ 00:04:39,000 --> 00:04:42,000
359
+ That's the encryption process how it works.
360
+
361
+ 91
362
+ 00:04:42,000 --> 00:04:47,000
363
+ But there are some advantages and disadvantages with this particular system.
364
+
365
+ 92
366
+ 00:04:48,000 --> 00:04:51,000
367
+ First of all, its advantages.
368
+
369
+ 93
370
+ 00:04:51,000 --> 00:04:53,000
371
+ Well, it solves a problem of key distribution.
372
+
373
+ 94
374
+ 00:04:53,000 --> 00:04:55,000
375
+ You notice that we can all communicate.
376
+
377
+ 95
378
+ 00:04:55,000 --> 00:04:59,000
379
+ There's no there's no need to share keys, right?
380
+
381
+ 96
382
+ 00:04:59,000 --> 00:05:05,000
383
+ If you remember, the problem with symmetric encryption was how do we get the key across the network
384
+
385
+ 97
386
+ 00:05:05,000 --> 00:05:07,000
387
+ and how do we get the key from this guy to this guy.
388
+
389
+ 98
390
+ 00:05:07,000 --> 00:05:08,000
391
+ Well, this is not a problem anymore.
392
+
393
+ 99
394
+ 00:05:08,000 --> 00:05:11,000
395
+ Now I just take somebody's public key and I encrypt it and give it to them.
396
+
397
+ 100
398
+ 00:05:11,000 --> 00:05:18,000
399
+ Anyone that intercepts the connection between me and Mary can't decrypt it because they don't have Mary's
400
+
401
+ 101
402
+ 00:05:18,000 --> 00:05:18,000
403
+ private key.
404
+
405
+ 102
406
+ 00:05:19,000 --> 00:05:22,000
407
+ So it solves the problem of distribution of the key.
408
+
409
+ 103
410
+ 00:05:23,000 --> 00:05:25,000
411
+ You don't need to have a billion keys.
412
+
413
+ 104
414
+ 00:05:25,000 --> 00:05:28,000
415
+ You don't need to have keys between people.
416
+
417
+ 105
418
+ 00:05:28,000 --> 00:05:34,000
419
+ For example, all you need to do to find the number of keys and asymmetric that would be needed if you
420
+
421
+ 106
422
+ 00:05:34,000 --> 00:05:39,000
423
+ are using just pure asymmetric if you have two users, four keys, right?
424
+
425
+ 107
426
+ 00:05:39,000 --> 00:05:44,000
427
+ If you have eight people, each of them would just need two keys with 16 keys.
428
+
429
+ 108
430
+ 00:05:44,000 --> 00:05:45,000
431
+ That's it.
432
+
433
+ 109
434
+ 00:05:45,000 --> 00:05:46,000
435
+ This times it by two.
436
+
437
+ 110
438
+ 00:05:46,000 --> 00:05:46,000
439
+ Easy enough.
440
+
441
+ 111
442
+ 00:05:47,000 --> 00:05:52,000
443
+ So the key distribution, the key management is pretty easy.
444
+
445
+ 112
446
+ 00:05:53,000 --> 00:05:59,000
447
+ It provides a method for digital signature which is important for authentication and repudiation.
448
+
449
+ 113
450
+ 00:05:59,000 --> 00:06:03,000
451
+ It has the ability to do non-repudiation authentication.
452
+
453
+ 114
454
+ 00:06:03,000 --> 00:06:09,000
455
+ And the reason is because there is something unique to you.
456
+
457
+ 115
458
+ 00:06:10,000 --> 00:06:13,000
459
+ There's something unique to you which is your private key.
460
+
461
+ 116
462
+ 00:06:14,000 --> 00:06:16,000
463
+ Let me give you guys an example of this.
464
+
465
+ 117
466
+ 00:06:16,000 --> 00:06:18,000
467
+ Let's say there is Andrew.
468
+
469
+ 118
470
+ 00:06:19,000 --> 00:06:20,000
471
+ Andrew has a memo.
472
+
473
+ 119
474
+ 00:06:22,000 --> 00:06:22,000
475
+ That's me.
476
+
477
+ 120
478
+ 00:06:22,000 --> 00:06:26,000
479
+ I have a memo that I want to give to everybody in the company.
480
+
481
+ 121
482
+ 00:06:27,000 --> 00:06:32,000
483
+ If I encrypt now I have two keys, a public and a private key.
484
+
485
+ 122
486
+ 00:06:32,000 --> 00:06:38,000
487
+ Remember, if my public key encrypts, only my private key decrypts, if my private encrypts, only
488
+
489
+ 123
490
+ 00:06:38,000 --> 00:06:47,000
491
+ my public decrypts, my private key is given to no one in the entire world but my private, and my private
492
+
493
+ 124
494
+ 00:06:47,000 --> 00:06:48,000
495
+ key is given to no one in the world.
496
+
497
+ 125
498
+ 00:06:48,000 --> 00:06:50,000
499
+ But my public key is given to everyone in the world.
500
+
501
+ 126
502
+ 00:06:51,000 --> 00:06:59,000
503
+ What I could do is this I could encrypt this memo with my private key to get ciphertext.
504
+
505
+ 127
506
+ 00:07:00,000 --> 00:07:01,000
507
+ Okay.
508
+
509
+ 128
510
+ 00:07:01,000 --> 00:07:04,000
511
+ And then I could give this out to everybody in the business.
512
+
513
+ 129
514
+ 00:07:04,000 --> 00:07:06,000
515
+ Who can decrypt this memo?
516
+
517
+ 130
518
+ 00:07:07,000 --> 00:07:08,000
519
+ Everyone.
520
+
521
+ 131
522
+ 00:07:08,000 --> 00:07:09,000
523
+ Why?
524
+
525
+ 132
526
+ 00:07:09,000 --> 00:07:13,000
527
+ Because it was encrypted with the private key, not the public key.
528
+
529
+ 133
530
+ 00:07:13,000 --> 00:07:14,000
531
+ The public key.
532
+
533
+ 134
534
+ 00:07:14,000 --> 00:07:16,000
535
+ Everybody has my public key.
536
+
537
+ 135
538
+ 00:07:16,000 --> 00:07:17,000
539
+ Hence the name public.
540
+
541
+ 136
542
+ 00:07:17,000 --> 00:07:19,000
543
+ Well, why would I do that?
544
+
545
+ 137
546
+ 00:07:19,000 --> 00:07:21,000
547
+ Why would I encrypt something so the world can decrypt?
548
+
549
+ 138
550
+ 00:07:21,000 --> 00:07:23,000
551
+ It kind of defeats the purpose.
552
+
553
+ 139
554
+ 00:07:23,000 --> 00:07:26,000
555
+ No, the purpose is non-repudiation.
556
+
557
+ 140
558
+ 00:07:26,000 --> 00:07:29,000
559
+ The purpose is you would be 100% sure.
560
+
561
+ 141
562
+ 00:07:29,000 --> 00:07:32,000
563
+ And I cannot deny that that memo came from me.
564
+
565
+ 142
566
+ 00:07:32,000 --> 00:07:36,000
567
+ If you use my private key to decrypt the data, I'm sorry.
568
+
569
+ 143
570
+ 00:07:36,000 --> 00:07:42,000
571
+ My public key to decrypt the data, then, you know, it had to be encrypted with something only I have,
572
+
573
+ 144
574
+ 00:07:42,000 --> 00:07:44,000
575
+ which is my private key.
576
+
577
+ 145
578
+ 00:07:45,000 --> 00:07:51,000
579
+ So this forms the basis of a digital signature, which we'll talk about later in the course.
580
+
581
+ 146
582
+ 00:07:51,000 --> 00:07:53,000
583
+ So it does that versus symmetric.
584
+
585
+ 147
586
+ 00:07:53,000 --> 00:07:55,000
587
+ And you see symmetric encryption.
588
+
589
+ 148
590
+ 00:07:55,000 --> 00:07:56,000
591
+ Everybody was sharing a key.
592
+
593
+ 149
594
+ 00:07:56,000 --> 00:07:58,000
595
+ There was nothing unique to someone.
596
+
597
+ 150
598
+ 00:07:58,000 --> 00:08:01,000
599
+ Everybody had basically the same key.
600
+
601
+ 151
602
+ 00:08:01,000 --> 00:08:03,000
603
+ Everybody needed the same key to encrypt and decrypt the data.
604
+
605
+ 152
606
+ 00:08:03,000 --> 00:08:06,000
607
+ They were part of that communication.
608
+
609
+ 153
610
+ 00:08:07,000 --> 00:08:08,000
611
+ Now.
612
+
613
+ 154
614
+ 00:08:08,000 --> 00:08:09,000
615
+ It sounds good.
616
+
617
+ 155
618
+ 00:08:09,000 --> 00:08:12,000
619
+ No key distribution problem, right?
620
+
621
+ 156
622
+ 00:08:12,000 --> 00:08:13,000
623
+ No problem distributing the key.
624
+
625
+ 157
626
+ 00:08:13,000 --> 00:08:15,000
627
+ Okay, that's no problem doing that.
628
+
629
+ 158
630
+ 00:08:15,000 --> 00:08:17,000
631
+ We don't need a billion keys.
632
+
633
+ 159
634
+ 00:08:17,000 --> 00:08:18,000
635
+ We don't need a lot of keys.
636
+
637
+ 160
638
+ 00:08:18,000 --> 00:08:23,000
639
+ If we don't, you know, we have a lot of users, so key management is easy.
640
+
641
+ 161
642
+ 00:08:24,000 --> 00:08:28,000
643
+ Uh, we have this easy thing of doing digital signatures.
644
+
645
+ 162
646
+ 00:08:29,000 --> 00:08:32,000
647
+ But why don't we use it to encrypt bulk data?
648
+
649
+ 163
650
+ 00:08:32,000 --> 00:08:37,000
651
+ In today's world, we actually don't use asymmetric encryption to encrypt larger data.
652
+
653
+ 164
654
+ 00:08:37,000 --> 00:08:43,000
655
+ Now, basically any data for that matter, the actual private information per se, we don't actually
656
+
657
+ 165
658
+ 00:08:43,000 --> 00:08:49,000
659
+ use it to encrypt bulk data or large amounts of data because it is very slow.
660
+
661
+ 166
662
+ 00:08:50,000 --> 00:08:56,000
663
+ You see, it's computationally intensive, much more than symmetric encryption, making it slower for
664
+
665
+ 167
666
+ 00:08:56,000 --> 00:08:57,000
667
+ large amounts of data.
668
+
669
+ 168
670
+ 00:08:57,000 --> 00:09:00,000
671
+ It requires also a careful management of those private keys.
672
+
673
+ 169
674
+ 00:09:01,000 --> 00:09:03,000
675
+ If your private key is compromised, you need a new pair.
676
+
677
+ 170
678
+ 00:09:03,000 --> 00:09:05,000
679
+ And it's because of.
680
+
681
+ 171
682
+ 00:09:06,000 --> 00:09:08,000
683
+ This point right here.
684
+
685
+ 172
686
+ 00:09:08,000 --> 00:09:09,000
687
+ See that point right there?
688
+
689
+ 173
690
+ 00:09:09,000 --> 00:09:13,000
691
+ This computationally intensive?
692
+
693
+ 174
694
+ 00:09:14,000 --> 00:09:20,000
695
+ Uh, problem is really what doesn't make it replace symmetric.
696
+
697
+ 175
698
+ 00:09:20,000 --> 00:09:22,000
699
+ Somebody say is asymmetric going to replace symmetric.
700
+
701
+ 176
702
+ 00:09:22,000 --> 00:09:27,000
703
+ No it's not because it's you really can't use it for large blocks of data because it's too -- slow.
704
+
705
+ 177
706
+ 00:09:28,000 --> 00:09:31,000
707
+ So if you notice these two algorithms, they cancel each other out.
708
+
709
+ 178
710
+ 00:09:31,000 --> 00:09:33,000
711
+ So one is fast, one is slow.
712
+
713
+ 179
714
+ 00:09:33,000 --> 00:09:36,000
715
+ One has a problem with with distributing keys.
716
+
717
+ 180
718
+ 00:09:36,000 --> 00:09:40,000
719
+ One doesn't have this problem distributing keys one can't doesn't have something unique to the user.
720
+
721
+ 181
722
+ 00:09:40,000 --> 00:09:41,000
723
+ But this one does.
724
+
725
+ 182
726
+ 00:09:41,000 --> 00:09:46,000
727
+ It seems like all the bad is good here and all the bad, all the good is bad there.
728
+
729
+ 183
730
+ 00:09:47,000 --> 00:09:48,000
731
+ You get the point.
732
+
733
+ 184
734
+ 00:09:49,000 --> 00:09:50,000
735
+ So what do we do?
736
+
737
+ 185
738
+ 00:09:50,000 --> 00:09:52,000
739
+ Well, there's a way to combine them again.
740
+
741
+ 186
742
+ 00:09:52,000 --> 00:09:54,000
743
+ Hybrid cryptography is a video on that.
744
+
745
+ 187
746
+ 00:09:54,000 --> 00:09:55,000
747
+ Talk about that later.
748
+
749
+ 188
750
+ 00:09:56,000 --> 00:09:57,000
751
+ Now.
752
+
753
+ 189
754
+ 00:09:57,000 --> 00:10:05,000
755
+ Because things like it has ability to be unique to people, because it has that digital signature and
756
+
757
+ 190
758
+ 00:10:05,000 --> 00:10:06,000
759
+ the safe distribution of keys.
760
+
761
+ 191
762
+ 00:10:06,000 --> 00:10:10,000
763
+ It basically is a cornerstone for protecting all data on the internet today, because things like SSL
764
+
765
+ 192
766
+ 00:10:10,000 --> 00:10:11,000
767
+ can't work without it.
768
+
769
+ 193
770
+ 00:10:12,000 --> 00:10:14,000
771
+ So keep that in mind for now.
772
+
773
+ 194
774
+ 00:10:14,000 --> 00:10:18,000
775
+ I need you guys to understand what a what asymmetric is.
776
+
777
+ 195
778
+ 00:10:18,000 --> 00:10:19,000
779
+ Quick recap as we end this.
780
+
781
+ 196
782
+ 00:10:20,000 --> 00:10:22,000
783
+ Asymmetric is based on the principle of two keys.
784
+
785
+ 197
786
+ 00:10:22,000 --> 00:10:27,000
787
+ Everybody in the asymmetric realm has two keys a public key and a private key.
788
+
789
+ 198
790
+ 00:10:27,000 --> 00:10:31,000
791
+ The public key to give out to anyone the private key they keep only to themselves.
792
+
793
+ 199
794
+ 00:10:31,000 --> 00:10:36,000
795
+ When one key encrypts, only the other one can decrypt, they both encrypt and decrypt.
796
+
797
+ 200
798
+ 00:10:36,000 --> 00:10:36,000
799
+ So now.
800
+
801
+ 201
802
+ 00:10:38,000 --> 00:10:39,000
803
+ Pros and cons.
804
+
805
+ 202
806
+ 00:10:39,000 --> 00:10:45,000
807
+ The good thing is that it's easy to distribute keys because if the keys the secrets are not shared,
808
+
809
+ 203
810
+ 00:10:45,000 --> 00:10:47,000
811
+ you can give your public key to anyone.
812
+
813
+ 204
814
+ 00:10:47,000 --> 00:10:50,000
815
+ But if they encrypt, only your private key can can decrypt it.
816
+
817
+ 205
818
+ 00:10:51,000 --> 00:10:57,000
819
+ This is good because if there's something unique to your private key now, you can use it for non-repudiation,
820
+
821
+ 206
822
+ 00:10:57,000 --> 00:10:58,000
823
+ like with digital signatures.
824
+
825
+ 207
826
+ 00:10:59,000 --> 00:11:00,000
827
+ But what's bad about it?
828
+
829
+ 208
830
+ 00:11:00,000 --> 00:11:02,000
831
+ Well, it's too slow.
832
+
833
+ 209
834
+ 00:11:02,000 --> 00:11:06,000
835
+ It's very, very computationally intensive.
836
+
837
+ 210
838
+ 00:11:06,000 --> 00:11:09,000
839
+ And for those reasons you cannot use it to encrypt bulk data.
840
+
841
+ 211
842
+ 00:11:09,000 --> 00:11:14,000
843
+ So that way we have to find a way to encrypt bulk data, which we'll talk about coming up later in hybrid
844
+
845
+ 212
846
+ 00:11:14,000 --> 00:11:15,000
847
+ cryptography.
848
+
849
+ 213
850
+ 00:11:15,000 --> 00:11:19,000
851
+ But before we do that, let's take a look at some of the asymmetric algorithms.
852
+
07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt ADDED
@@ -0,0 +1,268 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ Okay, let's take a look at different asymmetric algorithms that you need to know or at least understand
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:07,000
7
+ for your exam.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:13,000
11
+ Now, you don't need to know the math behind them or how it works, but you do need to know what they
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:15,000
15
+ are and maybe some pros and cons about them.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:19,000
19
+ So let's go ahead and get started on this now.
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:27,000
23
+ The world's most famous asymmetric algorithm is RSA d most famous algorithm out there.
24
+
25
+ 7
26
+ 00:00:27,000 --> 00:00:34,000
27
+ I would say 80% of communications that utilizes certificates is basically going to run on RSA.
28
+
29
+ 8
30
+ 00:00:34,000 --> 00:00:43,000
31
+ Now, RSA is based on the difficulty of factoring the product of two large prime numbers.
32
+
33
+ 9
34
+ 00:00:43,000 --> 00:00:47,000
35
+ Now, I'm not going to get into the math, but that's something you probably might see on a question
36
+
37
+ 10
38
+ 00:00:47,000 --> 00:00:47,000
39
+ here and there.
40
+
41
+ 11
42
+ 00:00:47,000 --> 00:00:52,000
43
+ It does use as large key sizes from 1024 to 4096.
44
+
45
+ 12
46
+ 00:00:52,000 --> 00:00:57,000
47
+ Most of the RSA keys that I see is going to be 2048 bit.
48
+
49
+ 13
50
+ 00:00:58,000 --> 00:01:04,000
51
+ This is widely used in things like digital signatures, key exchanges and of course SSL, TLS.
52
+
53
+ 14
54
+ 00:01:05,000 --> 00:01:10,000
55
+ The other one is elliptic curve cryptography, now elliptic curve.
56
+
57
+ 15
58
+ 00:01:10,000 --> 00:01:13,000
59
+ This is based on a different form of math.
60
+
61
+ 16
62
+ 00:01:13,000 --> 00:01:18,000
63
+ The elliptic curves over a specific field a finite field.
64
+
65
+ 17
66
+ 00:01:18,000 --> 00:01:24,000
67
+ It offers a higher degree of security with a smaller key size compared to RSA now because it's a different
68
+
69
+ 18
70
+ 00:01:24,000 --> 00:01:25,000
71
+ form of math.
72
+
73
+ 19
74
+ 00:01:26,000 --> 00:01:32,000
75
+ It has the advantage of being very secure with a small key versus RSA.
76
+
77
+ 20
78
+ 00:01:32,000 --> 00:01:34,000
79
+ For it to be secure, it needs a big key.
80
+
81
+ 21
82
+ 00:01:34,000 --> 00:01:39,000
83
+ For example, like I said, most of the RSA keys ECC is 2048 bit.
84
+
85
+ 22
86
+ 00:01:41,000 --> 00:01:50,000
87
+ Notice that this one here, it says here that 256 bit key in ECC is considered as secure as a 3072 bit.
88
+
89
+ 23
90
+ 00:01:50,000 --> 00:01:52,000
91
+ So that's a giant thing if you think about it.
92
+
93
+ 24
94
+ 00:01:52,000 --> 00:01:57,000
95
+ 256 bit is has the same security as 3072.
96
+
97
+ 25
98
+ 00:01:57,000 --> 00:01:58,000
99
+ Now if you're thinking, well, why does that matter so much?
100
+
101
+ 26
102
+ 00:01:58,000 --> 00:02:07,000
103
+ Because the bigger the key, the more CPU you need, the more memory you need to store that key.
104
+
105
+ 27
106
+ 00:02:07,000 --> 00:02:10,000
107
+ Now if you're thinking, well, it's only bits, it's not that much, right?
108
+
109
+ 28
110
+ 00:02:10,000 --> 00:02:19,000
111
+ If you get four gigs of if you have four gigabyte of memory, that's 32 billion bits of memory in your
112
+
113
+ 29
114
+ 00:02:19,000 --> 00:02:19,000
115
+ computer.
116
+
117
+ 30
118
+ 00:02:19,000 --> 00:02:20,000
119
+ And this is only four.
120
+
121
+ 31
122
+ 00:02:20,000 --> 00:02:21,000
123
+ But remember, if you're a server.
124
+
125
+ 32
126
+ 00:02:22,000 --> 00:02:28,000
127
+ And you have thousands or millions of connections, and you're managing all the keys for all these connections,
128
+
129
+ 33
130
+ 00:02:28,000 --> 00:02:30,000
131
+ which is going to get bogged down pretty quickly.
132
+
133
+ 34
134
+ 00:02:30,000 --> 00:02:31,000
135
+ All right.
136
+
137
+ 35
138
+ 00:02:31,000 --> 00:02:32,000
139
+ Did you know four gigs is 32 billion?
140
+
141
+ 36
142
+ 00:02:32,000 --> 00:02:33,000
143
+ Did you know that?
144
+
145
+ 37
146
+ 00:02:34,000 --> 00:02:36,000
147
+ Four gigabyte is 32 billion bits.
148
+
149
+ 38
150
+ 00:02:37,000 --> 00:02:39,000
151
+ If you don't know, you better study some A-plus.
152
+
153
+ 39
154
+ 00:02:39,000 --> 00:02:41,000
155
+ Learn your conversion.
156
+
157
+ 40
158
+ 00:02:41,000 --> 00:02:44,000
159
+ Uh, so EC is getting more popular.
160
+
161
+ 41
162
+ 00:02:44,000 --> 00:02:50,000
163
+ I want to mention it was taught that EC was going to replace RSA at some point due to its efficiency.
164
+
165
+ 42
166
+ 00:02:50,000 --> 00:02:54,000
167
+ I haven't really seen that yet, but supposedly EC is replace it.
168
+
169
+ 43
170
+ 00:02:54,000 --> 00:02:54,000
171
+ Why?
172
+
173
+ 44
174
+ 00:02:54,000 --> 00:02:58,000
175
+ It's going to give you more security, smaller key size and it basically does everything.
176
+
177
+ 45
178
+ 00:02:58,000 --> 00:02:59,000
179
+ RSA.
180
+
181
+ 46
182
+ 00:03:00,000 --> 00:03:01,000
183
+ Thus.
184
+
185
+ 47
186
+ 00:03:01,000 --> 00:03:06,000
187
+ Now the other two are also famous, just not as famous as those two.
188
+
189
+ 48
190
+ 00:03:06,000 --> 00:03:09,000
191
+ Diffie-Hellman was the first.
192
+
193
+ 49
194
+ 00:03:10,000 --> 00:03:10,000
195
+ The first.
196
+
197
+ 50
198
+ 00:03:10,000 --> 00:03:15,000
199
+ I'm pretty sure the first is, uh, asymmetric algorithm out there.
200
+
201
+ 51
202
+ 00:03:15,000 --> 00:03:17,000
203
+ It was created by two guys, Diffie and Hellman.
204
+
205
+ 52
206
+ 00:03:18,000 --> 00:03:23,000
207
+ Uh, this here was created for the passing of secret keys or symmetric keys.
208
+
209
+ 53
210
+ 00:03:23,000 --> 00:03:24,000
211
+ That was its objectives.
212
+
213
+ 54
214
+ 00:03:24,000 --> 00:03:29,000
215
+ It wasn't really meant to encrypt data or do any of the other things like RSA and ECC does.
216
+
217
+ 55
218
+ 00:03:31,000 --> 00:03:35,000
219
+ Uh, it's most used again is to pass the secret keys that was out there.
220
+
221
+ 56
222
+ 00:03:35,000 --> 00:03:37,000
223
+ The other one was Elgamal.
224
+
225
+ 57
226
+ 00:03:38,000 --> 00:03:45,000
227
+ And this here was basically based on Diffie-Hellman, uh, and it provides a basis of other algorithms.
228
+
229
+ 58
230
+ 00:03:45,000 --> 00:03:47,000
231
+ And this is really where this one was.
232
+
233
+ 59
234
+ 00:03:47,000 --> 00:03:50,000
235
+ So the most used is going to be RSA.
236
+
237
+ 60
238
+ 00:03:51,000 --> 00:03:54,000
239
+ ECC and Diffie-Hellman.
240
+
241
+ 61
242
+ 00:03:54,000 --> 00:03:58,000
243
+ Out there, there's going to be the most used one for your exam.
244
+
245
+ 62
246
+ 00:03:58,000 --> 00:04:05,000
247
+ I really don't need you guys to memorize all the bit, strings and or key sizes out there for these
248
+
249
+ 63
250
+ 00:04:05,000 --> 00:04:11,000
251
+ algorithms, but I do need you guys to know this is a symmetric this is an asymmetric algorithm.
252
+
253
+ 64
254
+ 00:04:11,000 --> 00:04:12,000
255
+ Here are the pros.
256
+
257
+ 65
258
+ 00:04:12,000 --> 00:04:15,000
259
+ And here is the cons of using symmetric and asymmetric.
260
+
261
+ 66
262
+ 00:04:15,000 --> 00:04:17,000
263
+ That's generally what your exam asks.
264
+
265
+ 67
266
+ 00:04:17,000 --> 00:04:19,000
267
+ So make sure you note them for your tests.
268
+
07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt ADDED
@@ -0,0 +1,488 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ In this video, I'm going to teach you how to combine asymmetric and symmetric to form the perfect cryptosystem.
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:09,000
7
+ This is called hybrid cryptography.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:12,000
11
+ And before I get into it, I want to point out something.
12
+
13
+ 4
14
+ 00:00:12,000 --> 00:00:14,000
15
+ A lot of security guys don't know this.
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:20,000
19
+ A lot of people read books and different watch different videos about symmetric and asymmetric and things
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:24,000
23
+ there and think that, for example, asymmetric is implemented by itself.
24
+
25
+ 7
26
+ 00:00:24,000 --> 00:00:25,000
27
+ It's not.
28
+
29
+ 8
30
+ 00:00:25,000 --> 00:00:26,000
31
+ Let me show you guys something.
32
+
33
+ 9
34
+ 00:00:26,000 --> 00:00:28,000
35
+ So here is the Wikipedia article on hybrid cryptography.
36
+
37
+ 10
38
+ 00:00:28,000 --> 00:00:30,000
39
+ I know, I know what you're gonna say, okay.
40
+
41
+ 11
42
+ 00:00:30,000 --> 00:00:33,000
43
+ You know, it's not the best system out there, but it's it's good enough.
44
+
45
+ 12
46
+ 00:00:34,000 --> 00:00:35,000
47
+ Hybrid cryptosystem.
48
+
49
+ 13
50
+ 00:00:36,000 --> 00:00:37,000
51
+ I'm just going to go down here.
52
+
53
+ 14
54
+ 00:00:37,000 --> 00:00:38,000
55
+ I want to read this part here for you.
56
+
57
+ 15
58
+ 00:00:38,000 --> 00:00:46,000
59
+ Notice it says all practical implementations of public key cryptography today employ the use of a hybrid
60
+
61
+ 16
62
+ 00:00:46,000 --> 00:00:47,000
63
+ system.
64
+
65
+ 17
66
+ 00:00:48,000 --> 00:00:50,000
67
+ All okay.
68
+
69
+ 18
70
+ 00:00:50,000 --> 00:00:56,000
71
+ Basically any time we use asymmetric encryption it's never basically used by itself.
72
+
73
+ 19
74
+ 00:00:56,000 --> 00:01:03,000
75
+ All implementations of it that we use in the real world, and not just the theoretical world is based
76
+
77
+ 20
78
+ 00:01:03,000 --> 00:01:05,000
79
+ on a hybrid cryptosystem.
80
+
81
+ 21
82
+ 00:01:05,000 --> 00:01:09,000
83
+ And in this video I want you guys to learn what that is like.
84
+
85
+ 22
86
+ 00:01:09,000 --> 00:01:11,000
87
+ What exactly is a hybrid cryptosystem.
88
+
89
+ 23
90
+ 00:01:11,000 --> 00:01:14,000
91
+ And I want to draw you guys a quick diagram how it's done.
92
+
93
+ 24
94
+ 00:01:15,000 --> 00:01:16,000
95
+ So let's get let's get into this.
96
+
97
+ 25
98
+ 00:01:16,000 --> 00:01:19,000
99
+ So what exactly is a hybrid cryptosystem.
100
+
101
+ 26
102
+ 00:01:19,000 --> 00:01:24,000
103
+ Well as you can imagine it takes the it takes the good of symmetric.
104
+
105
+ 27
106
+ 00:01:24,000 --> 00:01:27,000
107
+ The good of asymmetric combines them.
108
+
109
+ 28
110
+ 00:01:27,000 --> 00:01:29,000
111
+ Remember one there basically were like opposites.
112
+
113
+ 29
114
+ 00:01:29,000 --> 00:01:31,000
115
+ What's good here is bad here.
116
+
117
+ 30
118
+ 00:01:31,000 --> 00:01:31,000
119
+ What's bad here.
120
+
121
+ 31
122
+ 00:01:31,000 --> 00:01:32,000
123
+ What's good here.
124
+
125
+ 32
126
+ 00:01:32,000 --> 00:01:34,000
127
+ So if we combine them we get the perfect system.
128
+
129
+ 33
130
+ 00:01:34,000 --> 00:01:35,000
131
+ That's really what it is.
132
+
133
+ 34
134
+ 00:01:36,000 --> 00:01:43,000
135
+ Basically, when we combine them, we're going to use the asymmetric algorithms for the secure key exchange.
136
+
137
+ 35
138
+ 00:01:43,000 --> 00:01:47,000
139
+ And then we're going to use the symmetric for encrypting the actual data.
140
+
141
+ 36
142
+ 00:01:47,000 --> 00:01:52,000
143
+ Remember something symmetric is good at encrypting bulk data.
144
+
145
+ 37
146
+ 00:01:52,000 --> 00:01:53,000
147
+ Asymmetric is not.
148
+
149
+ 38
150
+ 00:01:53,000 --> 00:01:56,000
151
+ But asymmetric doesn't have a problem of key exchange.
152
+
153
+ 39
154
+ 00:01:56,000 --> 00:01:59,000
155
+ Now if asymmetric has to encrypt.
156
+
157
+ 40
158
+ 00:02:00,000 --> 00:02:01,000
159
+ Just a symmetric key.
160
+
161
+ 41
162
+ 00:02:01,000 --> 00:02:04,000
163
+ It's cool because a symmetric key is pretty small.
164
+
165
+ 42
166
+ 00:02:04,000 --> 00:02:07,000
167
+ It's only 256 bits or 128 bit.
168
+
169
+ 43
170
+ 00:02:07,000 --> 00:02:12,000
171
+ It's not the size of a picture, which could be four megabytes, which would be 32 billion bits.
172
+
173
+ 44
174
+ 00:02:12,000 --> 00:02:18,000
175
+ So remember this in the process that I'm about to cover now, I'm going to cover this exact process.
176
+
177
+ 45
178
+ 00:02:18,000 --> 00:02:21,000
179
+ The text is listed here right now.
180
+
181
+ 46
182
+ 00:02:21,000 --> 00:02:24,000
183
+ So I want to show you the hybrid cryptography system.
184
+
185
+ 47
186
+ 00:02:24,000 --> 00:02:28,000
187
+ Now let's say there is Andy.
188
+
189
+ 48
190
+ 00:02:29,000 --> 00:02:31,000
191
+ And there's Mary.
192
+
193
+ 49
194
+ 00:02:31,000 --> 00:02:35,000
195
+ So we have Mary M-a-r-y and Andy.
196
+
197
+ 50
198
+ 00:02:35,000 --> 00:02:38,000
199
+ So I have a public private key.
200
+
201
+ 51
202
+ 00:02:38,000 --> 00:02:39,000
203
+ Public.
204
+
205
+ 52
206
+ 00:02:39,000 --> 00:02:40,000
207
+ Private key.
208
+
209
+ 53
210
+ 00:02:41,000 --> 00:02:44,000
211
+ Now, reality is, I don't really need keys here.
212
+
213
+ 54
214
+ 00:02:44,000 --> 00:02:47,000
215
+ I'm just putting it there because everybody technically the system has it.
216
+
217
+ 55
218
+ 00:02:47,000 --> 00:02:51,000
219
+ But remember, if you're on the internet and you're using things that you don't have any public private
220
+
221
+ 56
222
+ 00:02:51,000 --> 00:02:52,000
223
+ keys in your machine.
224
+
225
+ 57
226
+ 00:02:53,000 --> 00:02:54,000
227
+ Now here's how it works.
228
+
229
+ 58
230
+ 00:02:54,000 --> 00:03:00,000
231
+ So let's say I have data that I want to transfer to Mary.
232
+
233
+ 59
234
+ 00:03:01,000 --> 00:03:04,000
235
+ Here's what I'm going to do on my computer.
236
+
237
+ 60
238
+ 00:03:04,000 --> 00:03:07,000
239
+ I am going to generate a symmetric key.
240
+
241
+ 61
242
+ 00:03:07,000 --> 00:03:11,000
243
+ This symmetric key is known as a session key.
244
+
245
+ 62
246
+ 00:03:11,000 --> 00:03:15,000
247
+ The session key is a symmetric key like an AES session key.
248
+
249
+ 63
250
+ 00:03:16,000 --> 00:03:22,000
251
+ What I'm going to do is I'm going to encrypt this data with this to form ciphertext.
252
+
253
+ 64
254
+ 00:03:24,000 --> 00:03:25,000
255
+ Okay.
256
+
257
+ 65
258
+ 00:03:25,000 --> 00:03:32,000
259
+ So ciphertext is the data is encrypted with the symmetric key to form ciphertext.
260
+
261
+ 66
262
+ 00:03:32,000 --> 00:03:36,000
263
+ What I'm going to do is I'm going to then say hey Mary, send me your public key.
264
+
265
+ 67
266
+ 00:03:36,000 --> 00:03:39,000
267
+ Mary sends me her public key, but I'm not going to encrypt the data with it.
268
+
269
+ 68
270
+ 00:03:39,000 --> 00:03:41,000
271
+ The data has already been encrypted.
272
+
273
+ 69
274
+ 00:03:41,000 --> 00:03:44,000
275
+ What am I going to encrypt the symmetric key if you said that.
276
+
277
+ 70
278
+ 00:03:44,000 --> 00:03:44,000
279
+ Correct.
280
+
281
+ 71
282
+ 00:03:44,000 --> 00:03:46,000
283
+ So I have ciphertext data.
284
+
285
+ 72
286
+ 00:03:47,000 --> 00:03:51,000
287
+ And now I have ciphertext symmetric key.
288
+
289
+ 73
290
+ 00:03:52,000 --> 00:03:54,000
291
+ What I do is now I send this to Mary.
292
+
293
+ 74
294
+ 00:03:54,000 --> 00:04:03,000
295
+ Mary receives the ciphertext symmetric key and she receives ciphertext data.
296
+
297
+ 75
298
+ 00:04:03,000 --> 00:04:04,000
299
+ You guys see that?
300
+
301
+ 76
302
+ 00:04:04,000 --> 00:04:04,000
303
+ Yep.
304
+
305
+ 77
306
+ 00:04:05,000 --> 00:04:07,000
307
+ How does Mary get the data?
308
+
309
+ 78
310
+ 00:04:07,000 --> 00:04:14,000
311
+ Well, now Mary utilizes her private key to decrypt the symmetric key.
312
+
313
+ 79
314
+ 00:04:14,000 --> 00:04:18,000
315
+ Remember, the symmetric key was encrypted with her public, so it could only be decrypted with her
316
+
317
+ 80
318
+ 00:04:18,000 --> 00:04:19,000
319
+ private.
320
+
321
+ 81
322
+ 00:04:19,000 --> 00:04:23,000
323
+ And now Mary has the symmetric key.
324
+
325
+ 82
326
+ 00:04:23,000 --> 00:04:26,000
327
+ She then uses that symmetric key to decrypt the data.
328
+
329
+ 83
330
+ 00:04:26,000 --> 00:04:27,000
331
+ Now she has the pure data.
332
+
333
+ 84
334
+ 00:04:28,000 --> 00:04:32,000
335
+ So that is the process of asymmetric.
336
+
337
+ 85
338
+ 00:04:32,000 --> 00:04:34,000
339
+ So let's sorry hybrid cryptography.
340
+
341
+ 86
342
+ 00:04:34,000 --> 00:04:36,000
343
+ Let's do a quick quick review.
344
+
345
+ 87
346
+ 00:04:37,000 --> 00:04:37,000
347
+ Okay.
348
+
349
+ 88
350
+ 00:04:37,000 --> 00:04:39,000
351
+ So remember I don't need keys.
352
+
353
+ 89
354
+ 00:04:39,000 --> 00:04:40,000
355
+ So what do I do.
356
+
357
+ 90
358
+ 00:04:40,000 --> 00:04:44,000
359
+ I have the data I generate a symmetric key on this machine.
360
+
361
+ 91
362
+ 00:04:44,000 --> 00:04:50,000
363
+ I then encrypt that symmetric key uh with Mary's public key.
364
+
365
+ 92
366
+ 00:04:50,000 --> 00:04:52,000
367
+ See that I took it I gave it to her.
368
+
369
+ 93
370
+ 00:04:52,000 --> 00:04:56,000
371
+ She gave it to me, I encrypt it, and now I have ciphertext data.
372
+
373
+ 94
374
+ 00:04:57,000 --> 00:05:01,000
375
+ Uh, I have the ciphertext data, and I have ciphertext symmetric key and send it to her.
376
+
377
+ 95
378
+ 00:05:01,000 --> 00:05:03,000
379
+ Now I want you to watch this connection.
380
+
381
+ 96
382
+ 00:05:03,000 --> 00:05:08,000
383
+ If there's a hacker right here, the hacker is seeing ciphertext data and ciphertext symmetric key.
384
+
385
+ 97
386
+ 00:05:08,000 --> 00:05:10,000
387
+ Everything you basically see is ciphertext.
388
+
389
+ 98
390
+ 00:05:10,000 --> 00:05:12,000
391
+ He never sees plaintext.
392
+
393
+ 99
394
+ 00:05:12,000 --> 00:05:16,000
395
+ When she receives it, she uses her private key to decrypt the symmetric key.
396
+
397
+ 100
398
+ 00:05:17,000 --> 00:05:21,000
399
+ And then uses that symmetric key to decrypt the ciphertext data to get the data.
400
+
401
+ 101
402
+ 00:05:21,000 --> 00:05:30,000
403
+ So I got data from me to her using a combination of of symmetric and asymmetric keys.
404
+
405
+ 102
406
+ 00:05:30,000 --> 00:05:33,000
407
+ This is the most efficient way of doing this.
408
+
409
+ 103
410
+ 00:05:35,000 --> 00:05:40,000
411
+ Now hybrid cryptography system combines this.
412
+
413
+ 104
414
+ 00:05:40,000 --> 00:05:43,000
415
+ All right combines the efficiency of symmetric key.
416
+
417
+ 105
418
+ 00:05:43,000 --> 00:05:44,000
419
+ So we get notice the data.
420
+
421
+ 106
422
+ 00:05:44,000 --> 00:05:47,000
423
+ The bulk data was using the symmetric.
424
+
425
+ 107
426
+ 00:05:47,000 --> 00:05:55,000
427
+ And of course that incredible key exchange process or easy management of the keys in asymmetric was
428
+
429
+ 108
430
+ 00:05:55,000 --> 00:05:55,000
431
+ use.
432
+
433
+ 109
434
+ 00:05:56,000 --> 00:06:01,000
435
+ One of the great things is that even if a symmetric key is compromised, it only affects one session
436
+
437
+ 110
438
+ 00:06:01,000 --> 00:06:03,000
439
+ every time I encrypt data.
440
+
441
+ 111
442
+ 00:06:03,000 --> 00:06:05,000
443
+ Every session I make a brand new session key.
444
+
445
+ 112
446
+ 00:06:06,000 --> 00:06:08,000
447
+ This is very scalable and used in numerous systems.
448
+
449
+ 113
450
+ 00:06:08,000 --> 00:06:17,000
451
+ In fact, all implementations of things like SSL, all web connections nowadays is basically that what
452
+
453
+ 114
454
+ 00:06:17,000 --> 00:06:21,000
455
+ I showed you there, that diagram I wrote are just basically just draw it for you, as is the basis
456
+
457
+ 115
458
+ 00:06:21,000 --> 00:06:23,000
459
+ of the SSL handshake.
460
+
461
+ 116
462
+ 00:06:23,000 --> 00:06:29,000
463
+ There's more to it, but that's basically the basis of how the whole SSL handshake works.
464
+
465
+ 117
466
+ 00:06:30,000 --> 00:06:32,000
467
+ So all types of converters, email, VPNs and so on.
468
+
469
+ 118
470
+ 00:06:32,000 --> 00:06:40,000
471
+ Anywhere that we have a symmetric anywhere that is symmetric uses asymmetric encryption, we'll have
472
+
473
+ 119
474
+ 00:06:40,000 --> 00:06:42,000
475
+ hybrid cryptography okay.
476
+
477
+ 120
478
+ 00:06:42,000 --> 00:06:47,000
479
+ So you may want to watch that process again understand the pros and cons of it and the process.
480
+
481
+ 121
482
+ 00:06:47,000 --> 00:06:53,000
483
+ Don't worry too much about the algorithm, but just remember all practical implementations of asymmetric
484
+
485
+ 122
486
+ 00:06:53,000 --> 00:06:55,000
487
+ utilizes hybrid cryptography.
488
+
07 - Cryptography/011 Hashing OB 1.4_en.srt ADDED
@@ -0,0 +1,1600 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ In this video, we're going to get started in the beautiful world of cryptographic hashes.
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:11,000
7
+ Now we covered asymmetric and symmetric asymmetric and a asymmetric and symmetric works directly on
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:13,000
11
+ data and produces things like ciphertext.
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:15,000
15
+ In this one we're going to do something different.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:20,000
19
+ What we're going to be doing is we're going to be taking data of any length and turn it into a fixed
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:21,000
23
+ length hash.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:24,000
27
+ This doesn't actually encrypt the data at all.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:26,000
31
+ This is just a cryptographic number.
32
+
33
+ 9
34
+ 00:00:26,000 --> 00:00:31,000
35
+ It's basically a value that represents the data.
36
+
37
+ 10
38
+ 00:00:31,000 --> 00:00:35,000
39
+ It's not used to replace the data and it's not used to be decrypted.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:38,000
43
+ This is something that's best shown than me trying to explain it.
44
+
45
+ 12
46
+ 00:00:38,000 --> 00:00:39,000
47
+ Let me show it to you.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:42,000
51
+ And then we're going to get into the nitty gritty detail.
52
+
53
+ 14
54
+ 00:00:42,000 --> 00:00:44,000
55
+ I'm going to be showing you a hash function.
56
+
57
+ 15
58
+ 00:00:44,000 --> 00:00:49,000
59
+ The most used hash function on the planet basically is going to be Sha 256.
60
+
61
+ 16
62
+ 00:00:49,000 --> 00:00:52,000
63
+ We're going to get more into this function later on in the in these lessons.
64
+
65
+ 17
66
+ 00:00:52,000 --> 00:00:55,000
67
+ But let's take a look.
68
+
69
+ 18
70
+ 00:00:55,000 --> 00:00:57,000
71
+ So here I am at uh, this website.
72
+
73
+ 19
74
+ 00:00:57,000 --> 00:01:02,000
75
+ And this is going to be a live view of a cryptographic hash functions getting done.
76
+
77
+ 20
78
+ 00:01:02,000 --> 00:01:05,000
79
+ Now the link to this website is in the slides.
80
+
81
+ 21
82
+ 00:01:05,000 --> 00:01:06,000
83
+ So I want to show you guys something.
84
+
85
+ 22
86
+ 00:01:07,000 --> 00:01:12,000
87
+ I'm going to be entering my text at the bottom and at the bottom, at the top and at the bottom you're
88
+
89
+ 23
90
+ 00:01:12,000 --> 00:01:15,000
91
+ going to get your cryptographic hash output.
92
+
93
+ 24
94
+ 00:01:15,000 --> 00:01:15,000
95
+ Let's see.
96
+
97
+ 25
98
+ 00:01:15,000 --> 00:01:25,000
99
+ So I'm going to say did you guys know I have many certifications.
100
+
101
+ 26
102
+ 00:01:25,000 --> 00:01:32,000
103
+ Now I want you guys to watch something every single time I touch that keyboard.
104
+
105
+ 27
106
+ 00:01:33,000 --> 00:01:35,000
107
+ The whole hash function chain.
108
+
109
+ 28
110
+ 00:01:35,000 --> 00:01:38,000
111
+ You see this function, right.
112
+
113
+ 29
114
+ 00:01:38,000 --> 00:01:41,000
115
+ This particular output, this string.
116
+
117
+ 30
118
+ 00:01:42,000 --> 00:01:43,000
119
+ Represents this data.
120
+
121
+ 31
122
+ 00:01:44,000 --> 00:01:51,000
123
+ If this data is modified in its slightest, this entire string will change.
124
+
125
+ 32
126
+ 00:01:52,000 --> 00:01:55,000
127
+ For example, I want you guys to select on the screen.
128
+
129
+ 33
130
+ 00:01:55,000 --> 00:01:56,000
131
+ We make this bigger so we can all see.
132
+
133
+ 34
134
+ 00:01:58,000 --> 00:01:58,000
135
+ Okay.
136
+
137
+ 35
138
+ 00:01:59,000 --> 00:02:00,000
139
+ Select any value here.
140
+
141
+ 36
142
+ 00:02:00,000 --> 00:02:04,000
143
+ It doesn't matter what this any value, any one of these.
144
+
145
+ 37
146
+ 00:02:04,000 --> 00:02:06,000
147
+ Maybe you got this one or maybe this eight here.
148
+
149
+ 38
150
+ 00:02:06,000 --> 00:02:08,000
151
+ And I'm just going to click in the data.
152
+
153
+ 39
154
+ 00:02:08,000 --> 00:02:09,000
155
+ And I'm just going to add a period.
156
+
157
+ 40
158
+ 00:02:09,000 --> 00:02:10,000
159
+ That's it.
160
+
161
+ 41
162
+ 00:02:10,000 --> 00:02:11,000
163
+ I'm just going to add a period.
164
+
165
+ 42
166
+ 00:02:12,000 --> 00:02:13,000
167
+ Did it change.
168
+
169
+ 43
170
+ 00:02:13,000 --> 00:02:14,000
171
+ More than likely it changed.
172
+
173
+ 44
174
+ 00:02:14,000 --> 00:02:15,000
175
+ All right.
176
+
177
+ 45
178
+ 00:02:15,000 --> 00:02:17,000
179
+ This whole thing basically changes.
180
+
181
+ 46
182
+ 00:02:17,000 --> 00:02:19,000
183
+ Almost all those values will change.
184
+
185
+ 47
186
+ 00:02:20,000 --> 00:02:20,000
187
+ Let me continue.
188
+
189
+ 48
190
+ 00:02:20,000 --> 00:02:27,000
191
+ Notice that there's two main properties I need you guys to know every single time I type something.
192
+
193
+ 49
194
+ 00:02:28,000 --> 00:02:29,000
195
+ Uh, watch it change.
196
+
197
+ 50
198
+ 00:02:29,000 --> 00:02:31,000
199
+ But there's something else that's not changing.
200
+
201
+ 51
202
+ 00:02:31,000 --> 00:02:33,000
203
+ Let's let me see if you detect it.
204
+
205
+ 52
206
+ 00:02:33,000 --> 00:02:41,000
207
+ So I hope you will get more certs than I have.
208
+
209
+ 53
210
+ 00:02:42,000 --> 00:02:43,000
211
+ Okay.
212
+
213
+ 54
214
+ 00:02:43,000 --> 00:02:43,000
215
+ Nope.
216
+
217
+ 55
218
+ 00:02:43,000 --> 00:02:44,000
219
+ I put an extra space.
220
+
221
+ 56
222
+ 00:02:44,000 --> 00:02:45,000
223
+ Let me remove it.
224
+
225
+ 57
226
+ 00:02:45,000 --> 00:02:51,000
227
+ Notice every single time I type the hash is changing.
228
+
229
+ 58
230
+ 00:02:51,000 --> 00:02:53,000
231
+ But there's something not changing.
232
+
233
+ 59
234
+ 00:02:53,000 --> 00:02:56,000
235
+ And what's not changing is the size of this.
236
+
237
+ 60
238
+ 00:02:56,000 --> 00:02:58,000
239
+ This thing stays the same.
240
+
241
+ 61
242
+ 00:02:58,000 --> 00:03:00,000
243
+ Doesn't matter how much text I put.
244
+
245
+ 62
246
+ 00:03:00,000 --> 00:03:02,000
247
+ You see, if I copy this here.
248
+
249
+ 63
250
+ 00:03:04,000 --> 00:03:06,000
251
+ I paste it into that box.
252
+
253
+ 64
254
+ 00:03:06,000 --> 00:03:12,000
255
+ Once again, the hash changes, but the size of the hash is not changing.
256
+
257
+ 65
258
+ 00:03:12,000 --> 00:03:16,000
259
+ No matter what I put in here, the hash size of the hash will not change.
260
+
261
+ 66
262
+ 00:03:16,000 --> 00:03:22,000
263
+ See, if I go in here and I put and I keep doing, it doesn't matter how many times I copy paste it,
264
+
265
+ 67
266
+ 00:03:22,000 --> 00:03:23,000
267
+ it will not change.
268
+
269
+ 68
270
+ 00:03:24,000 --> 00:03:26,000
271
+ This is a very unique characteristics of this hash.
272
+
273
+ 69
274
+ 00:03:26,000 --> 00:03:32,000
275
+ You see this particular value represents all this data.
276
+
277
+ 70
278
+ 00:03:33,000 --> 00:03:39,000
279
+ So if anybody manipulates this data in any which way and you have this hash value.
280
+
281
+ 71
282
+ 00:03:39,000 --> 00:03:43,000
283
+ So let's say I send you the data all of this and I send you this hash.
284
+
285
+ 72
286
+ 00:03:44,000 --> 00:03:45,000
287
+ Okay.
288
+
289
+ 73
290
+ 00:03:45,000 --> 00:03:49,000
291
+ You'll be able to tell if anybody manipulated it, because if somebody manipulates this data, maybe
292
+
293
+ 74
294
+ 00:03:49,000 --> 00:03:52,000
295
+ they went in here after this morning, they put a space.
296
+
297
+ 75
298
+ 00:03:52,000 --> 00:03:53,000
299
+ Then of course, the hash will change.
300
+
301
+ 76
302
+ 00:03:53,000 --> 00:03:55,000
303
+ You would know somebody modified that somehow.
304
+
305
+ 77
306
+ 00:03:56,000 --> 00:03:57,000
307
+ And that's what hashing is.
308
+
309
+ 78
310
+ 00:03:57,000 --> 00:04:04,000
311
+ Hashing is about detecting modification of the data, the hash value, the string of characters that
312
+
313
+ 79
314
+ 00:04:04,000 --> 00:04:05,000
315
+ we saw.
316
+
317
+ 80
318
+ 00:04:05,000 --> 00:04:07,000
319
+ That was a 256 bit hash.
320
+
321
+ 81
322
+ 00:04:07,000 --> 00:04:10,000
323
+ What we saw here, this is 256 bit.
324
+
325
+ 82
326
+ 00:04:10,000 --> 00:04:12,000
327
+ It's just written.
328
+
329
+ 83
330
+ 00:04:13,000 --> 00:04:16,000
331
+ It's written in a different format than you would know in in binary.
332
+
333
+ 84
334
+ 00:04:16,000 --> 00:04:17,000
335
+ Okay.
336
+
337
+ 85
338
+ 00:04:17,000 --> 00:04:21,000
339
+ So in this particular one it's, uh, hexadecimal.
340
+
341
+ 86
342
+ 00:04:21,000 --> 00:04:23,000
343
+ So it's 0298F.
344
+
345
+ 87
346
+ 00:04:23,000 --> 00:04:26,000
347
+ Now it's a base 16.
348
+
349
+ 88
350
+ 00:04:26,000 --> 00:04:28,000
351
+ So don't worry too much about the specific math.
352
+
353
+ 89
354
+ 00:04:28,000 --> 00:04:29,000
355
+ Just know that this is 200.
356
+
357
+ 90
358
+ 00:04:29,000 --> 00:04:31,000
359
+ This is 256 bit hash.
360
+
361
+ 91
362
+ 00:04:31,000 --> 00:04:37,000
363
+ And any kind of changes in here will result in a change here.
364
+
365
+ 92
366
+ 00:04:37,000 --> 00:04:40,000
367
+ Now let's talk about these characteristics of this.
368
+
369
+ 93
370
+ 00:04:42,000 --> 00:04:45,000
371
+ Because there's a lot of things here we should be able to understand.
372
+
373
+ 94
374
+ 00:04:45,000 --> 00:04:49,000
375
+ Number one is that when it comes to hashing what are we doing.
376
+
377
+ 95
378
+ 00:04:49,000 --> 00:04:52,000
379
+ Well we're converting an input of any length.
380
+
381
+ 96
382
+ 00:04:52,000 --> 00:04:54,000
383
+ Like I mentioned any length.
384
+
385
+ 97
386
+ 00:04:54,000 --> 00:04:59,000
387
+ It could be something as small as one bit all the way to terabytes of data.
388
+
389
+ 98
390
+ 00:04:59,000 --> 00:05:06,000
391
+ Doesn't matter into a fixed size string of text using a mathematical function.
392
+
393
+ 99
394
+ 00:05:06,000 --> 00:05:07,000
395
+ That's the hash function.
396
+
397
+ 100
398
+ 00:05:07,000 --> 00:05:08,000
399
+ That's what we just saw.
400
+
401
+ 101
402
+ 00:05:09,000 --> 00:05:14,000
403
+ Now a hash function takes data input data, like a message produces that fixed length hash.
404
+
405
+ 102
406
+ 00:05:14,000 --> 00:05:17,000
407
+ Now the thing to know is that it's you can't go back.
408
+
409
+ 103
410
+ 00:05:17,000 --> 00:05:18,000
411
+ And we'll talk about that in a minute.
412
+
413
+ 104
414
+ 00:05:20,000 --> 00:05:24,000
415
+ A good hash function produces a unique and distinct value for every single input.
416
+
417
+ 105
418
+ 00:05:24,000 --> 00:05:27,000
419
+ Even a small change results in a significant one.
420
+
421
+ 106
422
+ 00:05:27,000 --> 00:05:31,000
423
+ So that means that every time you type text in, you're going to get a different output.
424
+
425
+ 107
426
+ 00:05:31,000 --> 00:05:34,000
427
+ Every time the text changes, the output changed.
428
+
429
+ 108
430
+ 00:05:34,000 --> 00:05:35,000
431
+ Now we saw that.
432
+
433
+ 109
434
+ 00:05:35,000 --> 00:05:39,000
435
+ Now, just in case you don't have your following, just the slides, I give you a few examples.
436
+
437
+ 110
438
+ 00:05:39,000 --> 00:05:42,000
439
+ But you saw that here where that was this website I gave you.
440
+
441
+ 111
442
+ 00:05:42,000 --> 00:05:43,000
443
+ This is a link I was at.
444
+
445
+ 112
446
+ 00:05:43,000 --> 00:05:49,000
447
+ So you would just type in the value type in your text, the hash function, and then it would give you
448
+
449
+ 113
450
+ 00:05:49,000 --> 00:05:51,000
451
+ the different hashes.
452
+
453
+ 114
454
+ 00:05:51,000 --> 00:05:54,000
455
+ Now this particular website has more than just Sha 256.
456
+
457
+ 115
458
+ 00:05:54,000 --> 00:06:03,000
459
+ I think it has MD5 three shot 253 356 or I'm sorry 384 512 this is a variety of different ones there.
460
+
461
+ 116
462
+ 00:06:03,000 --> 00:06:10,000
463
+ Now there are some things that I want to talk about in terms of hashing, right.
464
+
465
+ 117
466
+ 00:06:10,000 --> 00:06:13,000
467
+ Some characteristics that we want to be familiar with.
468
+
469
+ 118
470
+ 00:06:13,000 --> 00:06:16,000
471
+ Number one is that it's deterministic.
472
+
473
+ 119
474
+ 00:06:16,000 --> 00:06:26,000
475
+ The same input always produces the same output every single time you hash that text.
476
+
477
+ 120
478
+ 00:06:26,000 --> 00:06:31,000
479
+ It should always give you that exact exact output.
480
+
481
+ 121
482
+ 00:06:31,000 --> 00:06:34,000
483
+ If the text is modified, the output is different.
484
+
485
+ 122
486
+ 00:06:34,000 --> 00:06:41,000
487
+ And I want to show you guys, uh, I want to show you guys this, uh, in their.
488
+
489
+ 123
490
+ 00:06:42,000 --> 00:06:43,000
491
+ So here's what I'm going to do.
492
+
493
+ 124
494
+ 00:06:45,000 --> 00:06:47,000
495
+ I'm going to highlight all this and I'm going to.
496
+
497
+ 125
498
+ 00:06:49,000 --> 00:06:51,000
499
+ Put I have.
500
+
501
+ 126
502
+ 00:06:51,000 --> 00:06:53,000
503
+ I want to show you guys something because this is going to make more sense.
504
+
505
+ 127
506
+ 00:06:53,000 --> 00:06:55,000
507
+ Have I have many certs.
508
+
509
+ 128
510
+ 00:06:55,000 --> 00:06:55,000
511
+ All right.
512
+
513
+ 129
514
+ 00:06:55,000 --> 00:06:56,000
515
+ This is my message.
516
+
517
+ 130
518
+ 00:06:56,000 --> 00:07:02,000
519
+ Every time I do this, every time I type this text, it should give me this exact hash.
520
+
521
+ 131
522
+ 00:07:02,000 --> 00:07:07,000
523
+ Doesn't matter where any time you run this text it should always give you this hash.
524
+
525
+ 132
526
+ 00:07:07,000 --> 00:07:12,000
527
+ So let me just go here and I'm going to say Sha 256 online.
528
+
529
+ 133
530
+ 00:07:13,000 --> 00:07:14,000
531
+ I'm just going to go to another website.
532
+
533
+ 134
534
+ 00:07:15,000 --> 00:07:16,000
535
+ I'm just going to use theirs okay.
536
+
537
+ 135
538
+ 00:07:16,000 --> 00:07:17,000
539
+ This is another website.
540
+
541
+ 136
542
+ 00:07:17,000 --> 00:07:19,000
543
+ And let's drag this one here.
544
+
545
+ 137
546
+ 00:07:19,000 --> 00:07:22,000
547
+ So we have two inputs on our screen.
548
+
549
+ 138
550
+ 00:07:22,000 --> 00:07:27,000
551
+ So let's see if what I do here this this output should be matched in this one.
552
+
553
+ 139
554
+ 00:07:27,000 --> 00:07:28,000
555
+ So let's see if we get it right.
556
+
557
+ 140
558
+ 00:07:28,000 --> 00:07:32,000
559
+ So I'm going to take this I'm going to copy this I'm going to put it into this screen now.
560
+
561
+ 141
562
+ 00:07:32,000 --> 00:07:34,000
563
+ So again it's the same function just a different site.
564
+
565
+ 142
566
+ 00:07:35,000 --> 00:07:37,000
567
+ I'm just showing you that the output is going to match watch.
568
+
569
+ 143
570
+ 00:07:37,000 --> 00:07:41,000
571
+ So I just put that there and let's see if the output matches.
572
+
573
+ 144
574
+ 00:07:41,000 --> 00:07:43,000
575
+ Now I'm not going to go one by one here.
576
+
577
+ 145
578
+ 00:07:43,000 --> 00:07:46,000
579
+ But the first couple should be fine e f.
580
+
581
+ 146
582
+ 00:07:46,000 --> 00:07:48,000
583
+ Let's see this one.
584
+
585
+ 147
586
+ 00:07:48,000 --> 00:07:52,000
587
+ Output F90F90 okay.
588
+
589
+ 148
590
+ 00:07:52,000 --> 00:07:55,000
591
+ What is it n with this one ends in 3266.
592
+
593
+ 149
594
+ 00:07:55,000 --> 00:07:56,000
595
+ This one ends in three two, six, six.
596
+
597
+ 150
598
+ 00:07:56,000 --> 00:07:56,000
599
+ See that?
600
+
601
+ 151
602
+ 00:07:57,000 --> 00:07:59,000
603
+ So if I go in here and I say I have.
604
+
605
+ 152
606
+ 00:08:01,000 --> 00:08:04,000
607
+ 66 shirts.
608
+
609
+ 153
610
+ 00:08:04,000 --> 00:08:10,000
611
+ So if I go in here and I say same thing six.
612
+
613
+ 154
614
+ 00:08:12,000 --> 00:08:15,000
615
+ 66 certs should match.
616
+
617
+ 155
618
+ 00:08:15,000 --> 00:08:16,000
619
+ Let's see again.
620
+
621
+ 156
622
+ 00:08:16,000 --> 00:08:19,000
623
+ So look at this e f f.
624
+
625
+ 157
626
+ 00:08:20,000 --> 00:08:21,000
627
+ E f f.
628
+
629
+ 158
630
+ 00:08:21,000 --> 00:08:22,000
631
+ Okay, great.
632
+
633
+ 159
634
+ 00:08:22,000 --> 00:08:23,000
635
+ This matches perfectly.
636
+
637
+ 160
638
+ 00:08:23,000 --> 00:08:25,000
639
+ It ends in 0303.
640
+
641
+ 161
642
+ 00:08:25,000 --> 00:08:26,000
643
+ So this one ends in 0303.
644
+
645
+ 162
646
+ 00:08:27,000 --> 00:08:28,000
647
+ Exactly.
648
+
649
+ 163
650
+ 00:08:28,000 --> 00:08:34,000
651
+ So any time you type that text using that function, you should always get that output.
652
+
653
+ 164
654
+ 00:08:34,000 --> 00:08:36,000
655
+ That's what that's the point I'm trying to make here.
656
+
657
+ 165
658
+ 00:08:36,000 --> 00:08:43,000
659
+ Now that's important to understand because when we come to passwords, the world of password management
660
+
661
+ 166
662
+ 00:08:43,000 --> 00:08:46,000
663
+ you're going to need to know that, uh, okay.
664
+
665
+ 167
666
+ 00:08:46,000 --> 00:08:48,000
667
+ So it's deterministic.
668
+
669
+ 168
670
+ 00:08:48,000 --> 00:08:49,000
671
+ It's fast.
672
+
673
+ 169
674
+ 00:08:49,000 --> 00:08:52,000
675
+ It should be able it doesn't really matter the size of it.
676
+
677
+ 170
678
+ 00:08:52,000 --> 00:08:55,000
679
+ It should be able to compute the hash relatively quickly.
680
+
681
+ 171
682
+ 00:08:56,000 --> 00:08:58,000
683
+ It should be preimage resistant.
684
+
685
+ 172
686
+ 00:08:58,000 --> 00:09:01,000
687
+ Now this is something you have to understand.
688
+
689
+ 173
690
+ 00:09:01,000 --> 00:09:04,000
691
+ It is considered one way.
692
+
693
+ 174
694
+ 00:09:04,000 --> 00:09:07,000
695
+ What does that mean if I give you.
696
+
697
+ 175
698
+ 00:09:08,000 --> 00:09:16,000
699
+ A hash value, you should not be able to reconstruct the original input.
700
+
701
+ 176
702
+ 00:09:16,000 --> 00:09:19,000
703
+ Well, what does that mean?
704
+
705
+ 177
706
+ 00:09:19,000 --> 00:09:21,000
707
+ Well let's see.
708
+
709
+ 178
710
+ 00:09:21,000 --> 00:09:23,000
711
+ So if I give you.
712
+
713
+ 179
714
+ 00:09:25,000 --> 00:09:31,000
715
+ If I give you this value, there is no way you should be going back.
716
+
717
+ 180
718
+ 00:09:31,000 --> 00:09:32,000
719
+ It's one way.
720
+
721
+ 181
722
+ 00:09:32,000 --> 00:09:32,000
723
+ It's.
724
+
725
+ 182
726
+ 00:09:32,000 --> 00:09:35,000
727
+ Take the data, produce a cryptographic hash.
728
+
729
+ 183
730
+ 00:09:35,000 --> 00:09:42,000
731
+ You should never be able to turn this the cash value into the text itself.
732
+
733
+ 184
734
+ 00:09:43,000 --> 00:09:47,000
735
+ In fact, it's probably not even feasible because when you have large amounts of text, it's not feasible
736
+
737
+ 185
738
+ 00:09:48,000 --> 00:09:57,000
739
+ because you can have data that's 20MB, that's 160 bits being brought down to 256 bits.
740
+
741
+ 186
742
+ 00:09:58,000 --> 00:09:58,000
743
+ Okay.
744
+
745
+ 187
746
+ 00:09:58,000 --> 00:09:59,000
747
+ That's like me.
748
+
749
+ 188
750
+ 00:09:59,000 --> 00:10:03,000
751
+ You know, if you take a four megabyte file, that's 32 billion bits.
752
+
753
+ 189
754
+ 00:10:03,000 --> 00:10:08,000
755
+ That's like me giving you $256 and say, go make 4 billion, $32 million.
756
+
757
+ 190
758
+ 00:10:08,000 --> 00:10:10,000
759
+ Not very hard to do.
760
+
761
+ 191
762
+ 00:10:10,000 --> 00:10:15,000
763
+ So it is considered a one way function.
764
+
765
+ 192
766
+ 00:10:15,000 --> 00:10:15,000
767
+ Okay.
768
+
769
+ 193
770
+ 00:10:15,000 --> 00:10:17,000
771
+ What are some other function of this.
772
+
773
+ 194
774
+ 00:10:17,000 --> 00:10:18,000
775
+ Let's see.
776
+
777
+ 195
778
+ 00:10:19,000 --> 00:10:19,000
779
+ Okay.
780
+
781
+ 196
782
+ 00:10:19,000 --> 00:10:26,000
783
+ So the other thing here we have is going to be small changes leads to large differences.
784
+
785
+ 197
786
+ 00:10:26,000 --> 00:10:28,000
787
+ Now that means that we saw this earlier.
788
+
789
+ 198
790
+ 00:10:28,000 --> 00:10:32,000
791
+ You make one small change to to the text.
792
+
793
+ 199
794
+ 00:10:32,000 --> 00:10:36,000
795
+ Remember when I just added a space or just one letter change or put a period or something.
796
+
797
+ 200
798
+ 00:10:36,000 --> 00:10:38,000
799
+ The whole hash will change.
800
+
801
+ 201
802
+ 00:10:38,000 --> 00:10:40,000
803
+ This is called the avalanche effect.
804
+
805
+ 202
806
+ 00:10:40,000 --> 00:10:44,000
807
+ What that means is that basically it's like a cascading effect.
808
+
809
+ 203
810
+ 00:10:44,000 --> 00:10:46,000
811
+ Okay, you change it, then it changes the entire hash.
812
+
813
+ 204
814
+ 00:10:47,000 --> 00:10:51,000
815
+ Now, the one I want to spend a couple of minutes on is called collision resistance.
816
+
817
+ 205
818
+ 00:10:51,000 --> 00:10:53,000
819
+ What exactly is this?
820
+
821
+ 206
822
+ 00:10:53,000 --> 00:10:55,000
823
+ Well, you have to understand how this thing works.
824
+
825
+ 207
826
+ 00:10:55,000 --> 00:10:57,000
827
+ It basically takes data.
828
+
829
+ 208
830
+ 00:10:58,000 --> 00:11:01,000
831
+ Of any length and it produces this fixed length string of text.
832
+
833
+ 209
834
+ 00:11:01,000 --> 00:11:02,000
835
+ This hash.
836
+
837
+ 210
838
+ 00:11:03,000 --> 00:11:09,000
839
+ You see, collisions occur when two different messages produces the same hash.
840
+
841
+ 211
842
+ 00:11:09,000 --> 00:11:10,000
843
+ That's really bad.
844
+
845
+ 212
846
+ 00:11:11,000 --> 00:11:13,000
847
+ You see, you have to understand how it functions.
848
+
849
+ 213
850
+ 00:11:13,000 --> 00:11:15,000
851
+ And let's talk about how it functions.
852
+
853
+ 214
854
+ 00:11:15,000 --> 00:11:20,000
855
+ So like how do you end up with a collision.
856
+
857
+ 215
858
+ 00:11:21,000 --> 00:11:21,000
859
+ We.
860
+
861
+ 216
862
+ 00:11:21,000 --> 00:11:24,000
863
+ First of all, you have to understand the hash value.
864
+
865
+ 217
866
+ 00:11:24,000 --> 00:11:28,000
867
+ The hash value algorithm a hash algorithm comes in bit string.
868
+
869
+ 218
870
+ 00:11:28,000 --> 00:11:32,000
871
+ For example, Sha like we saw was 256.
872
+
873
+ 219
874
+ 00:11:32,000 --> 00:11:36,000
875
+ That means that the output that it's giving you is 256 bit.
876
+
877
+ 220
878
+ 00:11:37,000 --> 00:11:41,000
879
+ There's another famous one called MD5, although you shouldn't be using it.
880
+
881
+ 221
882
+ 00:11:41,000 --> 00:11:44,000
883
+ It was pretty famous that has 128 bit.
884
+
885
+ 222
886
+ 00:11:44,000 --> 00:11:52,000
887
+ And if you remember earlier in the video, when we say 128 bit 256 bits, that tells me that's those
888
+
889
+ 223
890
+ 00:11:52,000 --> 00:11:53,000
891
+ are the number of digits in the hash.
892
+
893
+ 224
894
+ 00:11:53,000 --> 00:11:55,000
895
+ So how many possible hash you can have?
896
+
897
+ 225
898
+ 00:11:55,000 --> 00:11:57,000
899
+ Well, the number of bits tell you that.
900
+
901
+ 226
902
+ 00:11:57,000 --> 00:12:06,000
903
+ So if it's 128 bit there's 2 to 128 number of hashes available to be used.
904
+
905
+ 227
906
+ 00:12:07,000 --> 00:12:12,000
907
+ It's not an unlimited number of hashes out there, it is just a fixed number of hashes.
908
+
909
+ 228
910
+ 00:12:12,000 --> 00:12:15,000
911
+ Although it's a big pool, it's still a pool.
912
+
913
+ 229
914
+ 00:12:15,000 --> 00:12:16,000
915
+ It's still a fixed number.
916
+
917
+ 230
918
+ 00:12:17,000 --> 00:12:22,000
919
+ For example, let's say I'm really, really crazy and I make a hash function.
920
+
921
+ 231
922
+ 00:12:22,000 --> 00:12:25,000
923
+ A hash function that's two bits.
924
+
925
+ 232
926
+ 00:12:25,000 --> 00:12:28,000
927
+ Two bits only gives me four possible hashes.
928
+
929
+ 233
930
+ 00:12:28,000 --> 00:12:38,000
931
+ So if you're using my for my hash function to to do to to hash your data with, it'll be easy to have
932
+
933
+ 234
934
+ 00:12:38,000 --> 00:12:43,000
935
+ multiple different data having the exact same hash because only four possible hashes.
936
+
937
+ 235
938
+ 00:12:44,000 --> 00:12:45,000
939
+ So.
940
+
941
+ 236
942
+ 00:12:45,000 --> 00:12:51,000
943
+ Because the hash functions of today uses like 128, 256, 384, 512.
944
+
945
+ 237
946
+ 00:12:52,000 --> 00:12:53,000
947
+ Crazy amount of hashes.
948
+
949
+ 238
950
+ 00:12:54,000 --> 00:12:57,000
951
+ Collisions are not very likely, but they're not impossible.
952
+
953
+ 239
954
+ 00:12:58,000 --> 00:13:00,000
955
+ And there is a paradox.
956
+
957
+ 240
958
+ 00:13:00,000 --> 00:13:04,000
959
+ I want to talk to you guys about today that makes it somewhat possible.
960
+
961
+ 241
962
+ 00:13:04,000 --> 00:13:15,000
963
+ So for example MD5, the hash function of MD5, MD5 is 128 bit two to the 128 is a number 38 zeros,
964
+
965
+ 242
966
+ 00:13:15,000 --> 00:13:16,000
967
+ 37 zeros.
968
+
969
+ 243
970
+ 00:13:16,000 --> 00:13:16,000
971
+ I forgot this number.
972
+
973
+ 244
974
+ 00:13:16,000 --> 00:13:18,000
975
+ It's a crazy big number.
976
+
977
+ 245
978
+ 00:13:18,000 --> 00:13:23,000
979
+ So what is the probability that two different messages produce the same hash?
980
+
981
+ 246
982
+ 00:13:23,000 --> 00:13:28,000
983
+ It's not impossible because again there's a fixed number of hashes, but it doesn't seem likely.
984
+
985
+ 247
986
+ 00:13:30,000 --> 00:13:32,000
987
+ I want to show you guys a couple of things.
988
+
989
+ 248
990
+ 00:13:32,000 --> 00:13:33,000
991
+ First of all I want to show you a collision.
992
+
993
+ 249
994
+ 00:13:33,000 --> 00:13:36,000
995
+ So here is a diagram that we have.
996
+
997
+ 250
998
+ 00:13:36,000 --> 00:13:39,000
999
+ So this is the normal this is the collision.
1000
+
1001
+ 251
1002
+ 00:13:39,000 --> 00:13:47,000
1003
+ So in the normal look at the text the red fox runs across the box box and input field hashes it.
1004
+
1005
+ 252
1006
+ 00:13:47,000 --> 00:13:53,000
1007
+ And he gets this this this uh this output the yellow fox different message hashes to get this.
1008
+
1009
+ 253
1010
+ 00:13:53,000 --> 00:13:54,000
1011
+ But they're different right.
1012
+
1013
+ 254
1014
+ 00:13:54,000 --> 00:13:55,000
1015
+ This is normal.
1016
+
1017
+ 255
1018
+ 00:13:55,000 --> 00:13:57,000
1019
+ Different messages, different hash.
1020
+
1021
+ 256
1022
+ 00:13:57,000 --> 00:14:04,000
1023
+ The collision occurs when you take the red fox and the yellow fox to different messages, hashes it
1024
+
1025
+ 257
1026
+ 00:14:04,000 --> 00:14:05,000
1027
+ with the same function.
1028
+
1029
+ 258
1030
+ 00:14:05,000 --> 00:14:09,000
1031
+ But now all of a sudden you have the exact same hash.
1032
+
1033
+ 259
1034
+ 00:14:09,000 --> 00:14:14,000
1035
+ This is the collision two different messages producing the same hash function.
1036
+
1037
+ 260
1038
+ 00:14:16,000 --> 00:14:19,000
1039
+ Now, this is a kind of a weakness.
1040
+
1041
+ 261
1042
+ 00:14:19,000 --> 00:14:20,000
1043
+ All right.
1044
+
1045
+ 262
1046
+ 00:14:20,000 --> 00:14:22,000
1047
+ MD5 has multiple collision.
1048
+
1049
+ 263
1050
+ 00:14:22,000 --> 00:14:23,000
1051
+ That's what you should never use it.
1052
+
1053
+ 264
1054
+ 00:14:24,000 --> 00:14:27,000
1055
+ Uh, you should be using Sha 256 and above.
1056
+
1057
+ 265
1058
+ 00:14:27,000 --> 00:14:32,000
1059
+ An example of this I want to mention is something we call a birthday attack against passwords.
1060
+
1061
+ 266
1062
+ 00:14:32,000 --> 00:14:34,000
1063
+ The birthday attack is like a password thing.
1064
+
1065
+ 267
1066
+ 00:14:35,000 --> 00:14:36,000
1067
+ Most people know it as a password.
1068
+
1069
+ 268
1070
+ 00:14:36,000 --> 00:14:37,000
1071
+ I'll explain what this is to you.
1072
+
1073
+ 269
1074
+ 00:14:37,000 --> 00:14:40,000
1075
+ The what's called the birthday paradox.
1076
+
1077
+ 270
1078
+ 00:14:41,000 --> 00:14:46,000
1079
+ So I'm going to give you guys and I'm gonna explain why this is related to hashing.
1080
+
1081
+ 271
1082
+ 00:14:46,000 --> 00:14:49,000
1083
+ I'm going to give you guys something to think about.
1084
+
1085
+ 272
1086
+ 00:14:49,000 --> 00:14:50,000
1087
+ All right.
1088
+
1089
+ 273
1090
+ 00:14:50,000 --> 00:14:52,000
1091
+ Here's a type of a math function.
1092
+
1093
+ 274
1094
+ 00:14:52,000 --> 00:14:53,000
1095
+ You have to do a little bit of math.
1096
+
1097
+ 275
1098
+ 00:14:53,000 --> 00:14:55,000
1099
+ Don't worry it's not complex.
1100
+
1101
+ 276
1102
+ 00:14:55,000 --> 00:14:57,000
1103
+ If I put 30 people in a room.
1104
+
1105
+ 277
1106
+ 00:14:58,000 --> 00:15:03,000
1107
+ What is the probability that any two people have the exact same birthday?
1108
+
1109
+ 278
1110
+ 00:15:03,000 --> 00:15:07,000
1111
+ In that year there's 365 possible combinations of birthday, right?
1112
+
1113
+ 279
1114
+ 00:15:07,000 --> 00:15:11,000
1115
+ January 1st, January 2nd, January 3rd, 365 combinations.
1116
+
1117
+ 280
1118
+ 00:15:12,000 --> 00:15:14,000
1119
+ There's 30 people in the room.
1120
+
1121
+ 281
1122
+ 00:15:14,000 --> 00:15:18,000
1123
+ If I was to ask you guys if we were to, um.
1124
+
1125
+ 282
1126
+ 00:15:20,000 --> 00:15:25,000
1127
+ If we were to just grab two people that any two people, what's the probability that if we grab any
1128
+
1129
+ 283
1130
+ 00:15:25,000 --> 00:15:27,000
1131
+ two people, they have the same birthday?
1132
+
1133
+ 284
1134
+ 00:15:27,000 --> 00:15:29,000
1135
+ Would you say that number is small?
1136
+
1137
+ 285
1138
+ 00:15:29,000 --> 00:15:30,000
1139
+ 1%, 2%.
1140
+
1141
+ 286
1142
+ 00:15:30,000 --> 00:15:31,000
1143
+ Would you say it's moderate?
1144
+
1145
+ 287
1146
+ 00:15:31,000 --> 00:15:33,000
1147
+ 30, 40, 50, 60%?
1148
+
1149
+ 288
1150
+ 00:15:33,000 --> 00:15:34,000
1151
+ Would you say it's high?
1152
+
1153
+ 289
1154
+ 00:15:34,000 --> 00:15:34,000
1155
+ 80?
1156
+
1157
+ 290
1158
+ 00:15:34,000 --> 00:15:35,000
1159
+ 90%.
1160
+
1161
+ 291
1162
+ 00:15:37,000 --> 00:15:39,000
1163
+ Well without me giving it to you.
1164
+
1165
+ 292
1166
+ 00:15:39,000 --> 00:15:40,000
1167
+ Let me just show you.
1168
+
1169
+ 293
1170
+ 00:15:40,000 --> 00:15:42,000
1171
+ So here I have.
1172
+
1173
+ 294
1174
+ 00:15:42,000 --> 00:15:45,000
1175
+ I went to Wikipedia and I looked up birthday attack.
1176
+
1177
+ 295
1178
+ 00:15:45,000 --> 00:15:48,000
1179
+ You see, the birthday attack is a brute force.
1180
+
1181
+ 296
1182
+ 00:15:48,000 --> 00:15:49,000
1183
+ Is a brute force collision.
1184
+
1185
+ 297
1186
+ 00:15:49,000 --> 00:15:50,000
1187
+ Attack?
1188
+
1189
+ 298
1190
+ 00:15:51,000 --> 00:15:54,000
1191
+ It works on something we call the birthday paradox.
1192
+
1193
+ 299
1194
+ 00:15:54,000 --> 00:15:55,000
1195
+ Now what?
1196
+
1197
+ 300
1198
+ 00:15:55,000 --> 00:15:56,000
1199
+ This is.
1200
+
1201
+ 301
1202
+ 00:15:56,000 --> 00:15:57,000
1203
+ This is what I was just explaining.
1204
+
1205
+ 302
1206
+ 00:16:00,000 --> 00:16:05,000
1207
+ A scenario where a teacher with a class of 30 students actually everyone's birthday to determine whether
1208
+
1209
+ 303
1210
+ 00:16:05,000 --> 00:16:08,000
1211
+ any two students have the same birthday.
1212
+
1213
+ 304
1214
+ 00:16:08,000 --> 00:16:14,000
1215
+ Although this may seem small, the probability of one student having the same birthday as any other
1216
+
1217
+ 305
1218
+ 00:16:14,000 --> 00:16:16,000
1219
+ is actually 70%.
1220
+
1221
+ 306
1222
+ 00:16:16,000 --> 00:16:23,000
1223
+ Now, most of my students generally say 1% or 2%, but in actuality it's actually 70%.
1224
+
1225
+ 307
1226
+ 00:16:23,000 --> 00:16:24,000
1227
+ It's not a small number.
1228
+
1229
+ 308
1230
+ 00:16:25,000 --> 00:16:31,000
1231
+ In fact, if you put, I believe it's 60 people in a room, there's a 90 or 99% people percentage that
1232
+
1233
+ 309
1234
+ 00:16:31,000 --> 00:16:34,000
1235
+ they're going to have two, two people are going to have the same birthday.
1236
+
1237
+ 310
1238
+ 00:16:35,000 --> 00:16:40,000
1239
+ And if you're wondering, what the hell does that have to do with passwords or hashing collision.
1240
+
1241
+ 311
1242
+ 00:16:40,000 --> 00:16:47,000
1243
+ You see, the birthday paradox teaches us a very important thing about the laws of probability.
1244
+
1245
+ 312
1246
+ 00:16:47,000 --> 00:16:50,000
1247
+ What seems improbable is actually more probable than we believe.
1248
+
1249
+ 313
1250
+ 00:16:50,000 --> 00:16:57,000
1251
+ Although it seems like 30 people with 365 combinations seems like a very small likelihood, it's actually
1252
+
1253
+ 314
1254
+ 00:16:57,000 --> 00:16:58,000
1255
+ very likely.
1256
+
1257
+ 315
1258
+ 00:16:58,000 --> 00:17:00,000
1259
+ You see, how does this relate to hashing?
1260
+
1261
+ 316
1262
+ 00:17:00,000 --> 00:17:01,000
1263
+ Is this.
1264
+
1265
+ 317
1266
+ 00:17:02,000 --> 00:17:08,000
1267
+ There's two to the 128 bit number of hashes when you use an MD5 hash.
1268
+
1269
+ 318
1270
+ 00:17:08,000 --> 00:17:10,000
1271
+ There's an unlimited number of messages.
1272
+
1273
+ 319
1274
+ 00:17:10,000 --> 00:17:16,000
1275
+ The probability of two messages having the same hash seems very unlikely because there's so many hashes.
1276
+
1277
+ 320
1278
+ 00:17:16,000 --> 00:17:19,000
1279
+ But the birthday paradox says actually there is.
1280
+
1281
+ 321
1282
+ 00:17:19,000 --> 00:17:22,000
1283
+ There is no way to defeat the birthday paradox.
1284
+
1285
+ 322
1286
+ 00:17:22,000 --> 00:17:23,000
1287
+ There's no way to stop it.
1288
+
1289
+ 323
1290
+ 00:17:23,000 --> 00:17:27,000
1291
+ It's just the laws of math, except if you increase the number of birthdays.
1292
+
1293
+ 324
1294
+ 00:17:27,000 --> 00:17:32,000
1295
+ So instead of having 365 put 1000 combinations, then that percentage drops, that 70 goes down.
1296
+
1297
+ 325
1298
+ 00:17:32,000 --> 00:17:37,000
1299
+ So the way to break it is to increase the pool of possible hashes.
1300
+
1301
+ 326
1302
+ 00:17:37,000 --> 00:17:40,000
1303
+ Or in this come in this one pool of possible birthdays.
1304
+
1305
+ 327
1306
+ 00:17:41,000 --> 00:17:42,000
1307
+ Now.
1308
+
1309
+ 328
1310
+ 00:17:43,000 --> 00:17:45,000
1311
+ How does a birthday attack relate to passwords?
1312
+
1313
+ 329
1314
+ 00:17:45,000 --> 00:17:47,000
1315
+ Well, first of all, just what a heads up.
1316
+
1317
+ 330
1318
+ 00:17:47,000 --> 00:17:52,000
1319
+ When we get to the password section, I'm going to tell you guys remember hashing all passwords are
1320
+
1321
+ 331
1322
+ 00:17:52,000 --> 00:17:52,000
1323
+ hash.
1324
+
1325
+ 332
1326
+ 00:17:52,000 --> 00:17:55,000
1327
+ Computers don't store your passwords.
1328
+
1329
+ 333
1330
+ 00:17:56,000 --> 00:17:59,000
1331
+ As password as a plaintext, it stores it as hashes.
1332
+
1333
+ 334
1334
+ 00:17:59,000 --> 00:18:00,000
1335
+ Let me show you guys something.
1336
+
1337
+ 335
1338
+ 00:18:02,000 --> 00:18:06,000
1339
+ So a computer if your password is password one.
1340
+
1341
+ 336
1342
+ 00:18:06,000 --> 00:18:09,000
1343
+ This is what the computer stores this.
1344
+
1345
+ 337
1346
+ 00:18:11,000 --> 00:18:11,000
1347
+ Okay.
1348
+
1349
+ 338
1350
+ 00:18:11,000 --> 00:18:14,000
1351
+ It does not store your plaintext password.
1352
+
1353
+ 339
1354
+ 00:18:14,000 --> 00:18:20,000
1355
+ All computers, all computing systems doesn't store this plaintext.
1356
+
1357
+ 340
1358
+ 00:18:20,000 --> 00:18:21,000
1359
+ It stores this.
1360
+
1361
+ 341
1362
+ 00:18:22,000 --> 00:18:28,000
1363
+ So when you type in your password as password one, it then rehashes this and matches it to what it
1364
+
1365
+ 342
1366
+ 00:18:28,000 --> 00:18:29,000
1367
+ has on file.
1368
+
1369
+ 343
1370
+ 00:18:30,000 --> 00:18:35,000
1371
+ Remember, it's one way even if people compromise your system and steal your steal the hash, they should
1372
+
1373
+ 344
1374
+ 00:18:35,000 --> 00:18:36,000
1375
+ never be able to work it backwards.
1376
+
1377
+ 345
1378
+ 00:18:36,000 --> 00:18:37,000
1379
+ Because remember what I said?
1380
+
1381
+ 346
1382
+ 00:18:37,000 --> 00:18:43,000
1383
+ Hashing is one way where the birthday paradox comes into play, or the birthday attack comes into play
1384
+
1385
+ 347
1386
+ 00:18:43,000 --> 00:18:44,000
1387
+ is like this.
1388
+
1389
+ 348
1390
+ 00:18:45,000 --> 00:18:49,000
1391
+ It comes into play when your password is car, car.
1392
+
1393
+ 349
1394
+ 00:18:49,000 --> 00:18:53,000
1395
+ And then I come to you and it says, hey man, I guess your password.
1396
+
1397
+ 350
1398
+ 00:18:53,000 --> 00:18:54,000
1399
+ And you're like, okay, what is it?
1400
+
1401
+ 351
1402
+ 00:18:54,000 --> 00:18:56,000
1403
+ And I say, it's van, van.
1404
+
1405
+ 352
1406
+ 00:18:56,000 --> 00:18:59,000
1407
+ And you're like, no, it's car.
1408
+
1409
+ 353
1410
+ 00:18:59,000 --> 00:19:00,000
1411
+ And I said, nope, it's van.
1412
+
1413
+ 354
1414
+ 00:19:00,000 --> 00:19:01,000
1415
+ So you say prove it.
1416
+
1417
+ 355
1418
+ 00:19:01,000 --> 00:19:03,000
1419
+ So I go to the machine.
1420
+
1421
+ 356
1422
+ 00:19:03,000 --> 00:19:08,000
1423
+ And I type in your username and I type the word van and boom, it logs me in.
1424
+
1425
+ 357
1426
+ 00:19:08,000 --> 00:19:09,000
1427
+ You like me.
1428
+
1429
+ 358
1430
+ 00:19:09,000 --> 00:19:11,000
1431
+ I change my password so I log out.
1432
+
1433
+ 359
1434
+ 00:19:11,000 --> 00:19:15,000
1435
+ Then you come, you type your same username, you type the word car and you press enter and boom.
1436
+
1437
+ 360
1438
+ 00:19:15,000 --> 00:19:16,000
1439
+ It logs you in too.
1440
+
1441
+ 361
1442
+ 00:19:16,000 --> 00:19:17,000
1443
+ It's odd.
1444
+
1445
+ 362
1446
+ 00:19:17,000 --> 00:19:20,000
1447
+ It's two different words logging into the same account.
1448
+
1449
+ 363
1450
+ 00:19:20,000 --> 00:19:23,000
1451
+ It's like this one account has two different password.
1452
+
1453
+ 364
1454
+ 00:19:23,000 --> 00:19:24,000
1455
+ Know what's happening?
1456
+
1457
+ 365
1458
+ 00:19:24,000 --> 00:19:26,000
1459
+ There is the collision of where.
1460
+
1461
+ 366
1462
+ 00:19:27,000 --> 00:19:28,000
1463
+ Password.
1464
+
1465
+ 367
1466
+ 00:19:28,000 --> 00:19:34,000
1467
+ One is producing this hash and another text is producing the same hash as password one.
1468
+
1469
+ 368
1470
+ 00:19:34,000 --> 00:19:39,000
1471
+ The computer thinks car and van is the same thing because it's the same hash.
1472
+
1473
+ 369
1474
+ 00:19:40,000 --> 00:19:41,000
1475
+ That's a birthday attack.
1476
+
1477
+ 370
1478
+ 00:19:41,000 --> 00:19:42,000
1479
+ How do you defeat it?
1480
+
1481
+ 371
1482
+ 00:19:42,000 --> 00:19:43,000
1483
+ Use a big hash.
1484
+
1485
+ 372
1486
+ 00:19:43,000 --> 00:19:45,000
1487
+ Don't use a 128 bit hash.
1488
+
1489
+ 373
1490
+ 00:19:45,000 --> 00:19:49,000
1491
+ Remember I said you can only beat the birthday attack if you increase the number of birthdays.
1492
+
1493
+ 374
1494
+ 00:19:49,000 --> 00:19:50,000
1495
+ How do you beat it?
1496
+
1497
+ 375
1498
+ 00:19:50,000 --> 00:19:52,000
1499
+ Don't use the same number.
1500
+
1501
+ 376
1502
+ 00:19:52,000 --> 00:19:54,000
1503
+ Don't use small birthdays.
1504
+
1505
+ 377
1506
+ 00:19:54,000 --> 00:19:56,000
1507
+ Don't use a pool with a small amount of birthdays.
1508
+
1509
+ 378
1510
+ 00:19:56,000 --> 00:19:56,000
1511
+ Use a big one.
1512
+
1513
+ 379
1514
+ 00:19:56,000 --> 00:19:57,000
1515
+ Don't use 128.
1516
+
1517
+ 380
1518
+ 00:19:57,000 --> 00:19:58,000
1519
+ Use 256.
1520
+
1521
+ 381
1522
+ 00:19:58,000 --> 00:20:00,000
1523
+ That's the one we should be using today.
1524
+
1525
+ 382
1526
+ 00:20:00,000 --> 00:20:05,000
1527
+ Sha 256 all right, a lot of stuff in hashing.
1528
+
1529
+ 383
1530
+ 00:20:05,000 --> 00:20:07,000
1531
+ But before I go, let's do a quick recap of hashing.
1532
+
1533
+ 384
1534
+ 00:20:07,000 --> 00:20:09,000
1535
+ So hash is a cryptographic function.
1536
+
1537
+ 385
1538
+ 00:20:09,000 --> 00:20:13,000
1539
+ It takes data of any length, produces a fixed length hash.
1540
+
1541
+ 386
1542
+ 00:20:13,000 --> 00:20:14,000
1543
+ It's a one way thing.
1544
+
1545
+ 387
1546
+ 00:20:14,000 --> 00:20:18,000
1547
+ You cannot take the the hash function and turn it back into the plaintext.
1548
+
1549
+ 388
1550
+ 00:20:18,000 --> 00:20:20,000
1551
+ It should be quick.
1552
+
1553
+ 389
1554
+ 00:20:20,000 --> 00:20:23,000
1555
+ In other words, the computation should be very, very fast.
1556
+
1557
+ 390
1558
+ 00:20:23,000 --> 00:20:28,000
1559
+ Any change to the data results in a change to the cryptographic hash.
1560
+
1561
+ 391
1562
+ 00:20:28,000 --> 00:20:29,000
1563
+ Why are we doing this?
1564
+
1565
+ 392
1566
+ 00:20:29,000 --> 00:20:30,000
1567
+ The big word is integrity.
1568
+
1569
+ 393
1570
+ 00:20:30,000 --> 00:20:34,000
1571
+ We're able to detect modification on the data and determine integrity.
1572
+
1573
+ 394
1574
+ 00:20:34,000 --> 00:20:37,000
1575
+ And remember what collisions are the.
1576
+
1577
+ 395
1578
+ 00:20:37,000 --> 00:20:39,000
1579
+ We should be able to resist collisions.
1580
+
1581
+ 396
1582
+ 00:20:39,000 --> 00:20:41,000
1583
+ And the way we do that is by using bigger hashes.
1584
+
1585
+ 397
1586
+ 00:20:41,000 --> 00:20:46,000
1587
+ Collision is when two messages produce the same, the exact same hash.
1588
+
1589
+ 398
1590
+ 00:20:47,000 --> 00:20:51,000
1591
+ An example of this is the birthday attack, which we just which we just spoke about.
1592
+
1593
+ 399
1594
+ 00:20:51,000 --> 00:20:55,000
1595
+ So so remember what the characteristics of hashes.
1596
+
1597
+ 400
1598
+ 00:20:55,000 --> 00:20:59,000
1599
+ And now let's take a look at the different functions in the in the next video.
1600
+
07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt ADDED
@@ -0,0 +1,240 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ Okay, before I get into this, I want you guys to remember I have a table at the end of this section
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:09,000
7
+ that's going to summarize everything that I'm about to cover with you guys.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:13,000
11
+ So this video we're going to be taking a look at all the different hash functions that are out there.
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:15,000
15
+ Once again, don't memorize all of this.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:20,000
19
+ I just need you to know which ones are hash functions, which one are symmetric functions, and which
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:22,000
23
+ ones are asymmetric functions or algorithms.
24
+
25
+ 7
26
+ 00:00:22,000 --> 00:00:23,000
27
+ Let's take a look.
28
+
29
+ 8
30
+ 00:00:23,000 --> 00:00:32,000
31
+ So when it comes to hashing algorithm uh Sha or the secure hash algorithm, those series is going to
32
+
33
+ 9
34
+ 00:00:32,000 --> 00:00:34,000
35
+ be the most famous one.
36
+
37
+ 10
38
+ 00:00:34,000 --> 00:00:41,000
39
+ In fact Sha two, which comes the 256 bit version of it, is one of the most popular hashing function
40
+
41
+ 11
42
+ 00:00:41,000 --> 00:00:42,000
43
+ on the planet.
44
+
45
+ 12
46
+ 00:00:43,000 --> 00:00:48,000
47
+ So the secure hash algorithm is a series of government hash functions.
48
+
49
+ 13
50
+ 00:00:48,000 --> 00:00:49,000
51
+ This is promoted by NIST.
52
+
53
+ 14
54
+ 00:00:49,000 --> 00:00:53,000
55
+ And if you know one thing in the world of security, if it's good enough for the government, it's generally
56
+
57
+ 15
58
+ 00:00:53,000 --> 00:00:54,000
59
+ good enough for us.
60
+
61
+ 16
62
+ 00:00:54,000 --> 00:00:59,000
63
+ The original Sha one was 160 bit hash.
64
+
65
+ 17
66
+ 00:00:59,000 --> 00:01:04,000
67
+ This one here should no longer be used because it is subject to collisions.
68
+
69
+ 18
70
+ 00:01:04,000 --> 00:01:07,000
71
+ Remember, how you beat collisions is by having a bigger hash function.
72
+
73
+ 19
74
+ 00:01:08,000 --> 00:01:11,000
75
+ Sha two came in a variety of sizes.
76
+
77
+ 20
78
+ 00:01:11,000 --> 00:01:13,000
79
+ Uh 256 bit.
80
+
81
+ 21
82
+ 00:01:13,000 --> 00:01:17,000
83
+ It came in 512 and it also was 384.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:18,000
87
+ I think this one came in.
88
+
89
+ 23
90
+ 00:01:18,000 --> 00:01:22,000
91
+ So it did came in multiple sizes.
92
+
93
+ 24
94
+ 00:01:22,000 --> 00:01:24,000
95
+ Now I don't need you guys to worry about the blocks.
96
+
97
+ 25
98
+ 00:01:24,000 --> 00:01:27,000
99
+ I just need you guys to know basically the bit sizes on that.
100
+
101
+ 26
102
+ 00:01:27,000 --> 00:01:32,000
103
+ There was a Sha three that came out that uh, is a newer version of that.
104
+
105
+ 27
106
+ 00:01:34,000 --> 00:01:37,000
107
+ One of the most famous old school one was MD5.
108
+
109
+ 28
110
+ 00:01:37,000 --> 00:01:40,000
111
+ Now MD5 should not be used.
112
+
113
+ 29
114
+ 00:01:40,000 --> 00:01:48,000
115
+ MD5 has a lot of collisions because it doesn't have a very large, um, output at 128 bit.
116
+
117
+ 30
118
+ 00:01:48,000 --> 00:01:51,000
119
+ Although it's big in today's world, it's not big anymore.
120
+
121
+ 31
122
+ 00:01:51,000 --> 00:01:53,000
123
+ It is subject to collisions.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:02:03,000
127
+ Now, the other one here is a ripe re and ripe MD uh or message digest.
128
+
129
+ 33
130
+ 00:02:03,000 --> 00:02:07,000
131
+ This is an alternative to the Sha algorithms that are out there.
132
+
133
+ 34
134
+ 00:02:07,000 --> 00:02:10,000
135
+ And these have a variety of different block sizes.
136
+
137
+ 35
138
+ 00:02:10,000 --> 00:02:14,000
139
+ Now I did put it on the text here, but I do summarize it for you guys right here.
140
+
141
+ 36
142
+ 00:02:15,000 --> 00:02:21,000
143
+ Realistically, I don't need you guys to know all this last column.
144
+
145
+ 37
146
+ 00:02:21,000 --> 00:02:23,000
147
+ What I do need you guys to know is to know this column.
148
+
149
+ 38
150
+ 00:02:23,000 --> 00:02:26,000
151
+ Know that these are basically.
152
+
153
+ 39
154
+ 00:02:28,000 --> 00:02:29,000
155
+ Uh, hash functions.
156
+
157
+ 40
158
+ 00:02:29,000 --> 00:02:35,000
159
+ So on the exam, if they give you something, a scenario that you have to use this particular algorithm
160
+
161
+ 41
162
+ 00:02:35,000 --> 00:02:40,000
163
+ for, like for example, if they send your encrypted data across a network, don't select any of these
164
+
165
+ 42
166
+ 00:02:40,000 --> 00:02:42,000
167
+ because these are hash functions.
168
+
169
+ 43
170
+ 00:02:42,000 --> 00:02:44,000
171
+ They don't encrypt data, right.
172
+
173
+ 44
174
+ 00:02:44,000 --> 00:02:45,000
175
+ They produce hash functions.
176
+
177
+ 45
178
+ 00:02:45,000 --> 00:02:46,000
179
+ They're used for integrity.
180
+
181
+ 46
182
+ 00:02:46,000 --> 00:02:48,000
183
+ So that's what you should know.
184
+
185
+ 47
186
+ 00:02:48,000 --> 00:02:53,000
187
+ But if you want to see what what algorithm can change, data can detect if data has been modified.
188
+
189
+ 48
190
+ 00:02:53,000 --> 00:02:56,000
191
+ Those hash functions, that's what they're there for.
192
+
193
+ 49
194
+ 00:02:56,000 --> 00:02:56,000
195
+ All right.
196
+
197
+ 50
198
+ 00:02:56,000 --> 00:02:59,000
199
+ So don't you know don't go crazy.
200
+
201
+ 51
202
+ 00:02:59,000 --> 00:02:59,000
203
+ Oh my God.
204
+
205
+ 52
206
+ 00:02:59,000 --> 00:03:03,000
207
+ And you know, you just maybe this column here you should know.
208
+
209
+ 53
210
+ 00:03:03,000 --> 00:03:04,000
211
+ And it's pretty easy right.
212
+
213
+ 54
214
+ 00:03:04,000 --> 00:03:05,000
215
+ Because.
216
+
217
+ 55
218
+ 00:03:05,000 --> 00:03:10,000
219
+ Ripemd sha md5, just the ones you're probably going to see.
220
+
221
+ 56
222
+ 00:03:10,000 --> 00:03:13,000
223
+ So it's basically only three of them you really should keep in mind.
224
+
225
+ 57
226
+ 00:03:14,000 --> 00:03:14,000
227
+ Okay.
228
+
229
+ 58
230
+ 00:03:14,000 --> 00:03:20,000
231
+ Make sure you know these, um, as a real life security person, just remember, Sha256 should be your
232
+
233
+ 59
234
+ 00:03:20,000 --> 00:03:21,000
235
+ minimum.
236
+
237
+ 60
238
+ 00:03:21,000 --> 00:03:28,000
239
+ Don't use hash functions that are generally under 256 bit in the world of security.
240
+
07 - Cryptography/013 Digital Signatures OB 1.4_en.srt ADDED
@@ -0,0 +1,636 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:07,000
3
+ So far we have covered a lot symmetric asymmetric hashing hybrid cryptography.
4
+
5
+ 2
6
+ 00:00:07,000 --> 00:00:10,000
7
+ So far we covered a lot in this topic.
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:14,000
11
+ We're going to be combining a lot of what we learned to produce a particular function that I need you
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:16,000
15
+ guys to know, because we use it a lot.
16
+
17
+ 5
18
+ 00:00:16,000 --> 00:00:19,000
19
+ And that's called a digital signature.
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:23,000
23
+ Now a digital signature is not a not a way to encrypt data.
24
+
25
+ 7
26
+ 00:00:23,000 --> 00:00:28,000
27
+ So it doesn't provide confidentiality, but it's a way that when you send data to someone, they know
28
+
29
+ 8
30
+ 00:00:28,000 --> 00:00:33,000
31
+ it came from you, you can prove it came from you and it wasn't modified.
32
+
33
+ 9
34
+ 00:00:33,000 --> 00:00:39,000
35
+ And a digital signature is going to utilize some of the things we learned in in asymmetric and hashing
36
+
37
+ 10
38
+ 00:00:39,000 --> 00:00:40,000
39
+ in order to get it done.
40
+
41
+ 11
42
+ 00:00:40,000 --> 00:00:46,000
43
+ So in this video, I want to go through what exactly is a digital signature and what is the process?
44
+
45
+ 12
46
+ 00:00:46,000 --> 00:00:50,000
47
+ What is the process to make a signature and to verify a signature?
48
+
49
+ 13
50
+ 00:00:50,000 --> 00:00:51,000
51
+ Let's get into it.
52
+
53
+ 14
54
+ 00:00:52,000 --> 00:00:55,000
55
+ So what exactly is a digital signature?
56
+
57
+ 15
58
+ 00:00:55,000 --> 00:01:02,000
59
+ Well, it's a cryptographic technique used to validate the authentic unity and integrity of a message
60
+
61
+ 16
62
+ 00:01:02,000 --> 00:01:03,000
63
+ software digital document.
64
+
65
+ 17
66
+ 00:01:03,000 --> 00:01:09,000
67
+ Now a lot of times we digitally sign things like digital certificates and even PDF files.
68
+
69
+ 18
70
+ 00:01:09,000 --> 00:01:11,000
71
+ Word documents can all be digitally signed.
72
+
73
+ 19
74
+ 00:01:11,000 --> 00:01:14,000
75
+ Emails very famous to be digitally signed.
76
+
77
+ 20
78
+ 00:01:14,000 --> 00:01:18,000
79
+ Also, when you're doing a digital signature, you must remember.
80
+
81
+ 21
82
+ 00:01:19,000 --> 00:01:25,000
83
+ A digital signature is authenticity or authentication, its integrity and non-repudiation.
84
+
85
+ 22
86
+ 00:01:25,000 --> 00:01:27,000
87
+ It is not confidentiality.
88
+
89
+ 23
90
+ 00:01:27,000 --> 00:01:30,000
91
+ The data goes in plain text.
92
+
93
+ 24
94
+ 00:01:30,000 --> 00:01:31,000
95
+ You have to remember this.
96
+
97
+ 25
98
+ 00:01:31,000 --> 00:01:40,000
99
+ So if I have an email that I digitally sign and I send you that email, the email goes in plain text.
100
+
101
+ 26
102
+ 00:01:40,000 --> 00:01:43,000
103
+ That means if if all I did was digitally sign it.
104
+
105
+ 27
106
+ 00:01:44,000 --> 00:01:46,000
107
+ And I sent it to you.
108
+
109
+ 28
110
+ 00:01:46,000 --> 00:01:47,000
111
+ And a hacker sniffs the line.
112
+
113
+ 29
114
+ 00:01:47,000 --> 00:01:50,000
115
+ The hacker would be able to read the email because the email is not encrypted.
116
+
117
+ 30
118
+ 00:01:50,000 --> 00:01:56,000
119
+ But when you receive it, you'll know that it came from me.
120
+
121
+ 31
122
+ 00:01:57,000 --> 00:02:01,000
123
+ I wouldn't be able to deny that it came from me.
124
+
125
+ 32
126
+ 00:02:01,000 --> 00:02:02,000
127
+ Non-repudiation.
128
+
129
+ 33
130
+ 00:02:02,000 --> 00:02:06,000
131
+ And you're going to be 100% sure it was never modified.
132
+
133
+ 34
134
+ 00:02:06,000 --> 00:02:07,000
135
+ All right.
136
+
137
+ 35
138
+ 00:02:07,000 --> 00:02:09,000
139
+ So that's these three things.
140
+
141
+ 36
142
+ 00:02:09,000 --> 00:02:11,000
143
+ Confirms the signature was created by a sender.
144
+
145
+ 37
146
+ 00:02:11,000 --> 00:02:14,000
147
+ So you'll know it came from me.
148
+
149
+ 38
150
+ 00:02:14,000 --> 00:02:17,000
151
+ And I can't deny that it came from me.
152
+
153
+ 39
154
+ 00:02:17,000 --> 00:02:17,000
155
+ All right.
156
+
157
+ 40
158
+ 00:02:17,000 --> 00:02:22,000
159
+ So the authenticity, the non-repudiation, and then you'll know it was never modified.
160
+
161
+ 41
162
+ 00:02:22,000 --> 00:02:24,000
163
+ That's the point that you guys need to get.
164
+
165
+ 42
166
+ 00:02:25,000 --> 00:02:29,000
167
+ Once again, digital signatures does not encrypt the data.
168
+
169
+ 43
170
+ 00:02:29,000 --> 00:02:31,000
171
+ The data is actually transferred in plain text.
172
+
173
+ 44
174
+ 00:02:31,000 --> 00:02:34,000
175
+ Now, if you want to encrypt the data, well, that's a whole different thing.
176
+
177
+ 45
178
+ 00:02:34,000 --> 00:02:41,000
179
+ Maybe then you can combine with SSL, IPsec or other types of secure, secure algorithms.
180
+
181
+ 46
182
+ 00:02:41,000 --> 00:02:45,000
183
+ But if you're just using digital signatures, you're not going to get that.
184
+
185
+ 47
186
+ 00:02:46,000 --> 00:02:52,000
187
+ Now in this video, I want to talk to you guys about the creation and the verification of it.
188
+
189
+ 48
190
+ 00:02:52,000 --> 00:03:00,000
191
+ I do have all the texts listed here, but I have the, uh, I have a process that I drew out that I
192
+
193
+ 49
194
+ 00:03:00,000 --> 00:03:02,000
195
+ want to go over with you that covers all of this.
196
+
197
+ 50
198
+ 00:03:02,000 --> 00:03:07,000
199
+ So if you're watching, if you're reading this instead of watching it, well, you guys can read this,
200
+
201
+ 51
202
+ 00:03:07,000 --> 00:03:12,000
203
+ but since you're with me, I'm going to explain it to you in this particular.
204
+
205
+ 52
206
+ 00:03:14,000 --> 00:03:15,000
207
+ In this.
208
+
209
+ 53
210
+ 00:03:15,000 --> 00:03:16,000
211
+ Uh, where is my.
212
+
213
+ 54
214
+ 00:03:16,000 --> 00:03:17,000
215
+ Here we go.
216
+
217
+ 55
218
+ 00:03:17,000 --> 00:03:18,000
219
+ In this process.
220
+
221
+ 56
222
+ 00:03:18,000 --> 00:03:20,000
223
+ So I watch you guys watch this.
224
+
225
+ 57
226
+ 00:03:20,000 --> 00:03:25,000
227
+ So I'm going to show you how we are going to generate a signature.
228
+
229
+ 58
230
+ 00:03:26,000 --> 00:03:26,000
231
+ Okay.
232
+
233
+ 59
234
+ 00:03:26,000 --> 00:03:28,000
235
+ We're going to generate a digital signature.
236
+
237
+ 60
238
+ 00:03:28,000 --> 00:03:30,000
239
+ We're going to attach it to a document send it to the receiver.
240
+
241
+ 61
242
+ 00:03:30,000 --> 00:03:31,000
243
+ Let's see how this is done.
244
+
245
+ 62
246
+ 00:03:31,000 --> 00:03:33,000
247
+ So here we have the sender and the.
248
+
249
+ 63
250
+ 00:03:35,000 --> 00:03:37,000
251
+ And the receiver.
252
+
253
+ 64
254
+ 00:03:37,000 --> 00:03:42,000
255
+ Mary I'm always sending Mary things because okay, so here's how it's done okay.
256
+
257
+ 65
258
+ 00:03:43,000 --> 00:03:46,000
259
+ You take a plain text message?
260
+
261
+ 66
262
+ 00:03:46,000 --> 00:03:48,000
263
+ This is the message.
264
+
265
+ 67
266
+ 00:03:48,000 --> 00:03:53,000
267
+ And then what you're going to do is you're going to hash it, hash the entire message.
268
+
269
+ 68
270
+ 00:03:53,000 --> 00:03:58,000
271
+ And this produces that cryptographic hash that, remember, if you remember in the hashing video was
272
+
273
+ 69
274
+ 00:03:58,000 --> 00:03:59,000
275
+ just a string of characters.
276
+
277
+ 70
278
+ 00:03:59,000 --> 00:04:01,000
279
+ Basically it produces the digest.
280
+
281
+ 71
282
+ 00:04:01,000 --> 00:04:03,000
283
+ Remember the digest hash.
284
+
285
+ 72
286
+ 00:04:03,000 --> 00:04:03,000
287
+ Same thing.
288
+
289
+ 73
290
+ 00:04:04,000 --> 00:04:15,000
291
+ Then what the sender does is the sender encrypts this digest with the sender's private key.
292
+
293
+ 74
294
+ 00:04:16,000 --> 00:04:18,000
295
+ That is.
296
+
297
+ 75
298
+ 00:04:18,000 --> 00:04:18,000
299
+ All right.
300
+
301
+ 76
302
+ 00:04:18,000 --> 00:04:20,000
303
+ Then they're using an RSA key here.
304
+
305
+ 77
306
+ 00:04:20,000 --> 00:04:22,000
307
+ That is the digital signature.
308
+
309
+ 78
310
+ 00:04:23,000 --> 00:04:24,000
311
+ So let's get this straight.
312
+
313
+ 79
314
+ 00:04:25,000 --> 00:04:26,000
315
+ If I'm the sender.
316
+
317
+ 80
318
+ 00:04:26,000 --> 00:04:27,000
319
+ I took the message.
320
+
321
+ 81
322
+ 00:04:28,000 --> 00:04:30,000
323
+ I hashed it.
324
+
325
+ 82
326
+ 00:04:30,000 --> 00:04:34,000
327
+ I did encrypt the hash with my private key.
328
+
329
+ 83
330
+ 00:04:34,000 --> 00:04:35,000
331
+ Not my public key.
332
+
333
+ 84
334
+ 00:04:36,000 --> 00:04:37,000
335
+ My private key.
336
+
337
+ 85
338
+ 00:04:37,000 --> 00:04:38,000
339
+ Why the private key?
340
+
341
+ 86
342
+ 00:04:38,000 --> 00:04:44,000
343
+ Because the only person in the world that has my private key is me.
344
+
345
+ 87
346
+ 00:04:44,000 --> 00:04:46,000
347
+ No one else.
348
+
349
+ 88
350
+ 00:04:46,000 --> 00:04:52,000
351
+ So a digital signature in its purest form is an encrypted hash.
352
+
353
+ 89
354
+ 00:04:52,000 --> 00:04:53,000
355
+ Really all it is?
356
+
357
+ 90
358
+ 00:04:53,000 --> 00:04:56,000
359
+ It's encrypted with an asymmetric algorithm.
360
+
361
+ 91
362
+ 00:04:56,000 --> 00:04:58,000
363
+ In this one they're using RSA.
364
+
365
+ 92
366
+ 00:04:58,000 --> 00:05:00,000
367
+ You can also use ECC here.
368
+
369
+ 93
370
+ 00:05:00,000 --> 00:05:08,000
371
+ So what I do is I take this digital signature and I attach it to the document and I send it to the receiver.
372
+
373
+ 94
374
+ 00:05:10,000 --> 00:05:13,000
375
+ Mary has the document okay.
376
+
377
+ 95
378
+ 00:05:14,000 --> 00:05:15,000
379
+ And the digital signature.
380
+
381
+ 96
382
+ 00:05:15,000 --> 00:05:18,000
383
+ But remember it's all going in plain text signatures.
384
+
385
+ 97
386
+ 00:05:18,000 --> 00:05:20,000
387
+ Everything is in plain text.
388
+
389
+ 98
390
+ 00:05:20,000 --> 00:05:21,000
391
+ What does Mary do?
392
+
393
+ 99
394
+ 00:05:21,000 --> 00:05:23,000
395
+ So Mary is like, okay, I got this signature.
396
+
397
+ 100
398
+ 00:05:23,000 --> 00:05:27,000
399
+ Mary is like, okay, I need to verify, you know, that this actually came from Andy.
400
+
401
+ 101
402
+ 00:05:27,000 --> 00:05:28,000
403
+ How is she going to do it?
404
+
405
+ 102
406
+ 00:05:28,000 --> 00:05:29,000
407
+ Next slide.
408
+
409
+ 103
410
+ 00:05:30,000 --> 00:05:31,000
411
+ How does she do it?
412
+
413
+ 104
414
+ 00:05:31,000 --> 00:05:31,000
415
+ Well.
416
+
417
+ 105
418
+ 00:05:32,000 --> 00:05:33,000
419
+ Here's what she's going to do.
420
+
421
+ 106
422
+ 00:05:34,000 --> 00:05:37,000
423
+ So receiver again.
424
+
425
+ 107
426
+ 00:05:37,000 --> 00:05:37,000
427
+ Mary.
428
+
429
+ 108
430
+ 00:05:40,000 --> 00:05:46,000
431
+ Mary has to go through a couple of things, but Mary does is she takes this digitally signed message.
432
+
433
+ 109
434
+ 00:05:46,000 --> 00:05:49,000
435
+ She removes the digital signature from it.
436
+
437
+ 110
438
+ 00:05:49,000 --> 00:05:51,000
439
+ So now she has the plain text message.
440
+
441
+ 111
442
+ 00:05:51,000 --> 00:05:58,000
443
+ She then hashes it with the same algorithm that I used to hash the original message, and she ends up
444
+
445
+ 112
446
+ 00:05:58,000 --> 00:05:58,000
447
+ with a digest.
448
+
449
+ 113
450
+ 00:05:59,000 --> 00:06:02,000
451
+ She then takes the digital signature right?
452
+
453
+ 114
454
+ 00:06:02,000 --> 00:06:09,000
455
+ And she decrypts it with my the sender's.
456
+
457
+ 115
458
+ 00:06:09,000 --> 00:06:11,000
459
+ Public key.
460
+
461
+ 116
462
+ 00:06:11,000 --> 00:06:12,000
463
+ Why the sender's public key?
464
+
465
+ 117
466
+ 00:06:12,000 --> 00:06:19,000
467
+ Because, remember, in the generation, it was the sender's private key that was used to.
468
+
469
+ 118
470
+ 00:06:20,000 --> 00:06:23,000
471
+ Encrypt the actual hash.
472
+
473
+ 119
474
+ 00:06:23,000 --> 00:06:28,000
475
+ So what she's doing here is she's decrypting the signature with the public key.
476
+
477
+ 120
478
+ 00:06:29,000 --> 00:06:32,000
479
+ If the private encrypts, the public has to decrypt that.
480
+
481
+ 121
482
+ 00:06:33,000 --> 00:06:36,000
483
+ Provides the message digest.
484
+
485
+ 122
486
+ 00:06:36,000 --> 00:06:41,000
487
+ So what she's going to do now is she's going to compare the hash that she generated from the message,
488
+
489
+ 123
490
+ 00:06:41,000 --> 00:06:45,000
491
+ and she's going to compare the hash that was generated from the signature she just decrypted.
492
+
493
+ 124
494
+ 00:06:45,000 --> 00:06:53,000
495
+ And she's going to see do they compare if the message is from the digital signatures matches.
496
+
497
+ 125
498
+ 00:06:54,000 --> 00:06:54,000
499
+ Right.
500
+
501
+ 126
502
+ 00:06:54,000 --> 00:06:58,000
503
+ If the if this digest matches this digest, then it could be trusted by.
504
+
505
+ 127
506
+ 00:06:59,000 --> 00:07:00,000
507
+ Well.
508
+
509
+ 128
510
+ 00:07:01,000 --> 00:07:05,000
511
+ If the two digests are matching, it shows that the message was never modified.
512
+
513
+ 129
514
+ 00:07:06,000 --> 00:07:06,000
515
+ Right.
516
+
517
+ 130
518
+ 00:07:06,000 --> 00:07:08,000
519
+ Because if there's any modification to digest would change.
520
+
521
+ 131
522
+ 00:07:08,000 --> 00:07:13,000
523
+ And she knows 100% that it came from me.
524
+
525
+ 132
526
+ 00:07:13,000 --> 00:07:13,000
527
+ Why?
528
+
529
+ 133
530
+ 00:07:13,000 --> 00:07:17,000
531
+ Because she used my public key to decrypt that.
532
+
533
+ 134
534
+ 00:07:17,000 --> 00:07:20,000
535
+ If she had used somebody else public key, it would never match.
536
+
537
+ 135
538
+ 00:07:20,000 --> 00:07:23,000
539
+ It would look like more garbage or more ciphertext.
540
+
541
+ 136
542
+ 00:07:24,000 --> 00:07:27,000
543
+ So that is the process of a digital signature.
544
+
545
+ 137
546
+ 00:07:28,000 --> 00:07:31,000
547
+ Now digital signatures are widely used.
548
+
549
+ 138
550
+ 00:07:31,000 --> 00:07:34,000
551
+ Now, if you by the way, if you don't understand this process and you want to do it, you know, watch
552
+
553
+ 139
554
+ 00:07:34,000 --> 00:07:35,000
555
+ this video a couple of times.
556
+
557
+ 140
558
+ 00:07:35,000 --> 00:07:38,000
559
+ But digital signatures are widely used.
560
+
561
+ 141
562
+ 00:07:38,000 --> 00:07:41,000
563
+ In fact, there's a whole standard on it.
564
+
565
+ 142
566
+ 00:07:41,000 --> 00:07:46,000
567
+ So one time that you may want to be familiar with is something we call the DSS or the digital signature
568
+
569
+ 143
570
+ 00:07:46,000 --> 00:07:52,000
571
+ standard, because when you produce a signature, the person has to know what algorithm you use, right?
572
+
573
+ 144
574
+ 00:07:52,000 --> 00:07:55,000
575
+ They have to know, did he use Sha256?
576
+
577
+ 145
578
+ 00:07:55,000 --> 00:07:55,000
579
+ 512.
580
+
581
+ 146
582
+ 00:07:55,000 --> 00:08:03,000
583
+ Sha Sha two Sha three uh, you could use ECC as the asymmetric or RSA.
584
+
585
+ 147
586
+ 00:08:04,000 --> 00:08:07,000
587
+ So there is a standard for this, right?
588
+
589
+ 148
590
+ 00:08:07,000 --> 00:08:13,000
591
+ So NSA created the digital digital signature algorithm.
592
+
593
+ 149
594
+ 00:08:13,000 --> 00:08:16,000
595
+ The digital signature algorithm utilizes either.
596
+
597
+ 150
598
+ 00:08:16,000 --> 00:08:20,000
599
+ So the DSA is either it's shot 2 or 3.
600
+
601
+ 151
602
+ 00:08:20,000 --> 00:08:28,000
603
+ With RSA there's another one called Ecdsa which is instead of using RSA they use elliptic curve.
604
+
605
+ 152
606
+ 00:08:28,000 --> 00:08:28,000
607
+ All right.
608
+
609
+ 153
610
+ 00:08:28,000 --> 00:08:32,000
611
+ So just be familiar that there is a signature standard for this.
612
+
613
+ 154
614
+ 00:08:33,000 --> 00:08:36,000
615
+ Digital signatures are really important digital signatures.
616
+
617
+ 155
618
+ 00:08:36,000 --> 00:08:43,000
619
+ When somebody signs a document you are 100% sure it came from that person and it was never modified.
620
+
621
+ 156
622
+ 00:08:43,000 --> 00:08:47,000
623
+ You have to remember that because I'm about to bring everything together when we talk about public key
624
+
625
+ 157
626
+ 00:08:47,000 --> 00:08:48,000
627
+ infrastructure.
628
+
629
+ 158
630
+ 00:08:48,000 --> 00:08:51,000
631
+ So remember that once a digital signature is done.
632
+
633
+ 159
634
+ 00:08:52,000 --> 00:08:59,000
635
+ You're 100% sure that it came from that person and it was never modified.
636
+
07 - Cryptography/014 Intro to PKI OB 1.4_en.srt ADDED
@@ -0,0 +1,124 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ In this video, I want to start the discussion of the public key infrastructure.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:10,000
7
+ But before we get into that, I want to go to Amazon and I want to clear up some things about Amazon
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:11,000
11
+ that we should know.
12
+
13
+ 4
14
+ 00:00:11,000 --> 00:00:13,000
15
+ Before we get into this topic, let's take a look.
16
+
17
+ 5
18
+ 00:00:13,000 --> 00:00:16,000
19
+ So here I am at Amazon.com.
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:19,000
23
+ Now the question is going to be how do I know?
24
+
25
+ 7
26
+ 00:00:19,000 --> 00:00:24,000
27
+ How does this computer know that this is Amazon.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:27,000
31
+ Like do you trust the browser?
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:34,000
35
+ Okay, it says Amazon.com on it, but how does this computer know that this is Amazon.com?
36
+
37
+ 10
38
+ 00:00:34,000 --> 00:00:36,000
39
+ Is there a trust factor?
40
+
41
+ 11
42
+ 00:00:36,000 --> 00:00:41,000
43
+ Did Amazon tell this computer something that says, hey, I'm Amazon.com and the computer is like,
44
+
45
+ 12
46
+ 00:00:41,000 --> 00:00:45,000
47
+ okay, well, I guess you are, but how can the machine verify that?
48
+
49
+ 13
50
+ 00:00:46,000 --> 00:00:51,000
51
+ Well, you guys probably already know the answer to this is because it has a certificate.
52
+
53
+ 14
54
+ 00:00:51,000 --> 00:00:55,000
55
+ This connection is secured using TLS.
56
+
57
+ 15
58
+ 00:00:55,000 --> 00:00:58,000
59
+ And how do we know connections are secured?
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:01:00,000
63
+ Well, on most browsers, if not all.
64
+
65
+ 17
66
+ 00:01:00,000 --> 00:01:08,000
67
+ When you look at a connection like on Amazon, you'll notice that we have a little lock icon.
68
+
69
+ 18
70
+ 00:01:08,000 --> 00:01:10,000
71
+ If I go to this icon, I click on it.
72
+
73
+ 19
74
+ 00:01:10,000 --> 00:01:12,000
75
+ It says the connection is secure.
76
+
77
+ 20
78
+ 00:01:12,000 --> 00:01:15,000
79
+ I click here and it says the certificate is valid.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:19,000
83
+ But what exactly is this particular certificate?
84
+
85
+ 22
86
+ 00:01:19,000 --> 00:01:23,000
87
+ What is the purpose of this certificate and what you know?
88
+
89
+ 23
90
+ 00:01:23,000 --> 00:01:30,000
91
+ What exactly is it doing that makes this computer trust that this is Amazon.com?
92
+
93
+ 24
94
+ 00:01:31,000 --> 00:01:39,000
95
+ A certificate is basically nothing more than a document that contains Amazon's public key and a signature
96
+
97
+ 25
98
+ 00:01:39,000 --> 00:01:43,000
99
+ from a certificate authority saying that that's actually Amazon in a nutshell.
100
+
101
+ 26
102
+ 00:01:43,000 --> 00:01:44,000
103
+ That's what it is.
104
+
105
+ 27
106
+ 00:01:44,000 --> 00:01:51,000
107
+ But in this section of the course, I'm going to go in depth into more into all the fields on that certificate.
108
+
109
+ 28
110
+ 00:01:51,000 --> 00:01:57,000
111
+ What exactly is a certificate authority and why is, you know, why do we need it?
112
+
113
+ 29
114
+ 00:01:57,000 --> 00:02:01,000
115
+ Why is it so important that your connection be trusted or secure?
116
+
117
+ 30
118
+ 00:02:01,000 --> 00:02:02,000
119
+ Okay.
120
+
121
+ 31
122
+ 00:02:02,000 --> 00:02:05,000
123
+ So let's go ahead and get started in this section.
124
+
07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt ADDED
@@ -0,0 +1,1176 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ In this video, I'm going to be going over the SSL handshake, something that you really have to understand,
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:10,000
7
+ not just for your exam, but exactly how this cryptography work.
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:17,000
11
+ When you buy something on Amazon or any website or any website that is secured using TLS or SSL.
12
+
13
+ 4
14
+ 00:00:17,000 --> 00:00:22,000
15
+ Now for this course and in particular this section, TLS and SSL is the same thing.
16
+
17
+ 5
18
+ 00:00:22,000 --> 00:00:26,000
19
+ So if I ever say SSL, TLS remember something SSL is not used anymore.
20
+
21
+ 6
22
+ 00:00:26,000 --> 00:00:31,000
23
+ SSL is replaced by TLS, but a lot of people still reference it.
24
+
25
+ 7
26
+ 00:00:31,000 --> 00:00:34,000
27
+ Like if you go online, you Google SSL certificate.
28
+
29
+ 8
30
+ 00:00:34,000 --> 00:00:36,000
31
+ They're not really SSL, they're all TLS certificate.
32
+
33
+ 9
34
+ 00:00:37,000 --> 00:00:42,000
35
+ So for argument's sake, we'll just say we'll just use the terms SSL for the remainder of the course.
36
+
37
+ 10
38
+ 00:00:42,000 --> 00:00:44,000
39
+ Remember it is actually TLS.
40
+
41
+ 11
42
+ 00:00:44,000 --> 00:00:46,000
43
+ Now let's get started.
44
+
45
+ 12
46
+ 00:00:46,000 --> 00:00:49,000
47
+ So in this video we want to talk about the SSL handshake.
48
+
49
+ 13
50
+ 00:00:49,000 --> 00:00:55,000
51
+ Now the presentation that I'm going to be using the diagram I'm going to be using comes from Ibm.com.
52
+
53
+ 14
54
+ 00:00:55,000 --> 00:01:01,000
55
+ And that particular link I will be sharing with you guys on the slide.
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:06,000
59
+ And I want to show you guys what that looks like now, so you can check it out whenever you get a minute.
60
+
61
+ 16
62
+ 00:01:06,000 --> 00:01:08,000
63
+ Uh, here's Ibm.com.
64
+
65
+ 17
66
+ 00:01:09,000 --> 00:01:12,000
67
+ This was last updated 2021 the SSL handshake.
68
+
69
+ 18
70
+ 00:01:12,000 --> 00:01:12,000
71
+ So I took this.
72
+
73
+ 19
74
+ 00:01:12,000 --> 00:01:13,000
75
+ I put it on the slide.
76
+
77
+ 20
78
+ 00:01:13,000 --> 00:01:18,000
79
+ Of course, I put the link here for you guys to review it also, and I want to go over this with you
80
+
81
+ 21
82
+ 00:01:19,000 --> 00:01:21,000
83
+ if you're asking yourself well why?
84
+
85
+ 22
86
+ 00:01:21,000 --> 00:01:25,000
87
+ Because this is going to explain to you at a high level overview.
88
+
89
+ 23
90
+ 00:01:25,000 --> 00:01:29,000
91
+ Exactly how does a connection work?
92
+
93
+ 24
94
+ 00:01:29,000 --> 00:01:36,000
95
+ Like when you go to Amazon.com and you try to purchase something, you go to Yahoo YouTube.
96
+
97
+ 25
98
+ 00:01:36,000 --> 00:01:37,000
99
+ It doesn't matter.
100
+
101
+ 26
102
+ 00:01:37,000 --> 00:01:39,000
103
+ They're all secure sites.
104
+
105
+ 27
106
+ 00:01:39,000 --> 00:01:43,000
107
+ In fact, all sites on the internet right now are secured using SSL.
108
+
109
+ 28
110
+ 00:01:43,000 --> 00:01:46,000
111
+ How exactly this whole encryption process work?
112
+
113
+ 29
114
+ 00:01:46,000 --> 00:01:47,000
115
+ Now I want to point out something.
116
+
117
+ 30
118
+ 00:01:47,000 --> 00:01:52,000
119
+ The SSL handshake presentation that I'm using from IBM is a high level.
120
+
121
+ 31
122
+ 00:01:52,000 --> 00:01:55,000
123
+ It's not very detailed and it's not very technical.
124
+
125
+ 32
126
+ 00:01:55,000 --> 00:01:56,000
127
+ For your exam.
128
+
129
+ 33
130
+ 00:01:56,000 --> 00:01:58,000
131
+ You don't need to be detailed and technical.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:02,000
135
+ If you take my course, I'll get more in depth into it.
136
+
137
+ 35
138
+ 00:02:02,000 --> 00:02:04,000
139
+ But for this course you don't need that.
140
+
141
+ 36
142
+ 00:02:04,000 --> 00:02:08,000
143
+ You just need to have a good understanding or a high level overview understanding.
144
+
145
+ 37
146
+ 00:02:08,000 --> 00:02:09,000
147
+ Let's get started on it.
148
+
149
+ 38
150
+ 00:02:09,000 --> 00:02:18,000
151
+ So I go to Amazon.com and here I am at Amazon and I can see that my connection is secure.
152
+
153
+ 39
154
+ 00:02:18,000 --> 00:02:21,000
155
+ And if you notice is it secure.
156
+
157
+ 40
158
+ 00:02:21,000 --> 00:02:22,000
159
+ Yeah, it's fully secured.
160
+
161
+ 41
162
+ 00:02:22,000 --> 00:02:25,000
163
+ Because if you notice I have an Https right here.
164
+
165
+ 42
166
+ 00:02:25,000 --> 00:02:28,000
167
+ So this is utilizing SSL.
168
+
169
+ 43
170
+ 00:02:28,000 --> 00:02:31,000
171
+ Now the question is going to be how do I know.
172
+
173
+ 44
174
+ 00:02:31,000 --> 00:02:32,000
175
+ Like it's actually working.
176
+
177
+ 45
178
+ 00:02:32,000 --> 00:02:34,000
179
+ And you know what's happening in the background.
180
+
181
+ 46
182
+ 00:02:34,000 --> 00:02:40,000
183
+ Well one of the things is that every single website you go to that is secure is going to have this little
184
+
185
+ 47
186
+ 00:02:40,000 --> 00:02:41,000
187
+ lock icon.
188
+
189
+ 48
190
+ 00:02:41,000 --> 00:02:42,000
191
+ So I'm going to click on this little lock icon.
192
+
193
+ 49
194
+ 00:02:42,000 --> 00:02:46,000
195
+ This lock icon tells me the connection is secure.
196
+
197
+ 50
198
+ 00:02:46,000 --> 00:02:49,000
199
+ And you can't have a secure connection without a certificate.
200
+
201
+ 51
202
+ 00:02:49,000 --> 00:02:52,000
203
+ So I'm going to go to connection to secure certificate is valid.
204
+
205
+ 52
206
+ 00:02:52,000 --> 00:02:53,000
207
+ I'm just going to click on this.
208
+
209
+ 53
210
+ 00:02:53,000 --> 00:02:56,000
211
+ This is Amazon certificate.
212
+
213
+ 54
214
+ 00:02:56,000 --> 00:02:58,000
215
+ Now what exactly is a certificate.
216
+
217
+ 55
218
+ 00:02:58,000 --> 00:03:04,000
219
+ Well a certificate really serves two main purpose in the world of encryption.
220
+
221
+ 56
222
+ 00:03:04,000 --> 00:03:09,000
223
+ Number one, it serves as a trusted as an external validation of trust.
224
+
225
+ 57
226
+ 00:03:09,000 --> 00:03:15,000
227
+ So right now Amazon is not saying that I'm Amazon because I'm Amazon.
228
+
229
+ 58
230
+ 00:03:16,000 --> 00:03:20,000
231
+ Amazon is telling your computer that it's Amazon.
232
+
233
+ 59
234
+ 00:03:20,000 --> 00:03:24,000
235
+ Not because I said it's Amazon or because Amazon said it's Amazon.
236
+
237
+ 60
238
+ 00:03:24,000 --> 00:03:31,000
239
+ It's saying that because this authority Digicert says that this is Amazon.com and this is important.
240
+
241
+ 61
242
+ 00:03:31,000 --> 00:03:35,000
243
+ External validation creates trust.
244
+
245
+ 62
246
+ 00:03:35,000 --> 00:03:36,000
247
+ Let me explain this to you.
248
+
249
+ 63
250
+ 00:03:37,000 --> 00:03:40,000
251
+ So I'm Andrew Ramsdale okay.
252
+
253
+ 64
254
+ 00:03:40,000 --> 00:03:44,000
255
+ I'm the guy with the 66 certifications, the world's best selling book.
256
+
257
+ 65
258
+ 00:03:45,000 --> 00:03:47,000
259
+ But do you know that for sure?
260
+
261
+ 66
262
+ 00:03:47,000 --> 00:03:49,000
263
+ Do you know if I'm that person?
264
+
265
+ 67
266
+ 00:03:49,000 --> 00:03:54,000
267
+ There is a guy that wrote the world's best selling book on Amazon for project management.
268
+
269
+ 68
270
+ 00:03:54,000 --> 00:03:58,000
271
+ There is a guy that made a, you know, a lot of different videos and has helped hundreds of thousands
272
+
273
+ 69
274
+ 00:03:58,000 --> 00:04:02,000
275
+ of people pass exams, but am I that person?
276
+
277
+ 70
278
+ 00:04:02,000 --> 00:04:03,000
279
+ Do you trust me?
280
+
281
+ 71
282
+ 00:04:03,000 --> 00:04:05,000
283
+ If I told you I'm Andrew, do you?
284
+
285
+ 72
286
+ 00:04:05,000 --> 00:04:06,000
287
+ How do you know?
288
+
289
+ 73
290
+ 00:04:06,000 --> 00:04:09,000
291
+ How do you know I am that person?
292
+
293
+ 74
294
+ 00:04:09,000 --> 00:04:10,000
295
+ How do you.
296
+
297
+ 75
298
+ 00:04:10,000 --> 00:04:12,000
299
+ You know I am that entity.
300
+
301
+ 76
302
+ 00:04:13,000 --> 00:04:15,000
303
+ Well, I'm just telling you I am.
304
+
305
+ 77
306
+ 00:04:15,000 --> 00:04:16,000
307
+ Is that okay if I tell you?
308
+
309
+ 78
310
+ 00:04:16,000 --> 00:04:19,000
311
+ Or would you like for me to produce my driver's license?
312
+
313
+ 79
314
+ 00:04:19,000 --> 00:04:20,000
315
+ Like if I told you.
316
+
317
+ 80
318
+ 00:04:20,000 --> 00:04:21,000
319
+ Okay.
320
+
321
+ 81
322
+ 00:04:21,000 --> 00:04:23,000
323
+ Here's my driver's license.
324
+
325
+ 82
326
+ 00:04:23,000 --> 00:04:24,000
327
+ Would you believe me then?
328
+
329
+ 83
330
+ 00:04:25,000 --> 00:04:27,000
331
+ So if you say yes, okay.
332
+
333
+ 84
334
+ 00:04:27,000 --> 00:04:34,000
335
+ If you show me your license, that shows me that your Andrew and that picture matches you, then you,
336
+
337
+ 85
338
+ 00:04:34,000 --> 00:04:36,000
339
+ then you're more likely or you will believe it.
340
+
341
+ 86
342
+ 00:04:36,000 --> 00:04:41,000
343
+ That tells me something that tells me that you don't trust me.
344
+
345
+ 87
346
+ 00:04:41,000 --> 00:04:44,000
347
+ You trust the DMV.
348
+
349
+ 88
350
+ 00:04:44,000 --> 00:04:46,000
351
+ You have a trust with the DMV.
352
+
353
+ 89
354
+ 00:04:46,000 --> 00:04:53,000
355
+ And if the DMV says that this guy is Andrew, then you trust that you're like, okay, that that guy
356
+
357
+ 90
358
+ 00:04:53,000 --> 00:04:54,000
359
+ must be Andrew.
360
+
361
+ 91
362
+ 00:04:54,000 --> 00:04:56,000
363
+ Do you understand what I'm saying here?
364
+
365
+ 92
366
+ 00:04:56,000 --> 00:05:00,000
367
+ What I'm trying to tell you is you don't have a trust with me.
368
+
369
+ 93
370
+ 00:05:00,000 --> 00:05:02,000
371
+ You have a trust with the DMV.
372
+
373
+ 94
374
+ 00:05:02,000 --> 00:05:08,000
375
+ And because the DMV is saying that I'm Andrew now, you believe, okay, he's Andrew, but you don't
376
+
377
+ 95
378
+ 00:05:08,000 --> 00:05:10,000
379
+ believe a word that comes out of my mouth.
380
+
381
+ 96
382
+ 00:05:10,000 --> 00:05:13,000
383
+ You believe what the DMV is saying?
384
+
385
+ 97
386
+ 00:05:13,000 --> 00:05:15,000
387
+ And why do you believe the DMV?
388
+
389
+ 98
390
+ 00:05:15,000 --> 00:05:16,000
391
+ That's the question.
392
+
393
+ 99
394
+ 00:05:16,000 --> 00:05:18,000
395
+ Why do you believe the DMV?
396
+
397
+ 100
398
+ 00:05:18,000 --> 00:05:25,000
399
+ Well, because I couldn't get the license if I didn't show my passport.
400
+
401
+ 101
402
+ 00:05:25,000 --> 00:05:27,000
403
+ Bank statements.
404
+
405
+ 102
406
+ 00:05:27,000 --> 00:05:29,000
407
+ Uh, I forgot all the documents.
408
+
409
+ 103
410
+ 00:05:29,000 --> 00:05:29,000
411
+ Right?
412
+
413
+ 104
414
+ 00:05:29,000 --> 00:05:30,000
415
+ You got to get in New York.
416
+
417
+ 105
418
+ 00:05:30,000 --> 00:05:31,000
419
+ You got to get all these points.
420
+
421
+ 106
422
+ 00:05:31,000 --> 00:05:32,000
423
+ Right.
424
+
425
+ 107
426
+ 00:05:32,000 --> 00:05:34,000
427
+ So I had to show all these identity documents.
428
+
429
+ 108
430
+ 00:05:34,000 --> 00:05:37,000
431
+ And that's the reason why you trust the DMV.
432
+
433
+ 109
434
+ 00:05:37,000 --> 00:05:40,000
435
+ Well, you see, in computers, it's the same thing.
436
+
437
+ 110
438
+ 00:05:41,000 --> 00:05:42,000
439
+ Computers.
440
+
441
+ 111
442
+ 00:05:42,000 --> 00:05:45,000
443
+ Don't trust a website to say it's a web.
444
+
445
+ 112
446
+ 00:05:45,000 --> 00:05:48,000
447
+ It doesn't trust the website to say it's that website.
448
+
449
+ 113
450
+ 00:05:49,000 --> 00:05:50,000
451
+ It trusses.
452
+
453
+ 114
454
+ 00:05:50,000 --> 00:05:55,000
455
+ Your computer has a pre list of authorities that it trusts.
456
+
457
+ 115
458
+ 00:05:55,000 --> 00:05:57,000
459
+ Quote unquote DMVs.
460
+
461
+ 116
462
+ 00:05:57,000 --> 00:05:59,000
463
+ These are going to be called certificate authorities.
464
+
465
+ 117
466
+ 00:05:59,000 --> 00:06:02,000
467
+ Your computer has a pre list of certificate authorities that it trusts.
468
+
469
+ 118
470
+ 00:06:02,000 --> 00:06:07,000
471
+ Similarly to how your mind has a list of people that it trusts like DMVs.
472
+
473
+ 119
474
+ 00:06:08,000 --> 00:06:14,000
475
+ So when these authorities give out, quote unquote, driver's license, we'll call them certificates,
476
+
477
+ 120
478
+ 00:06:14,000 --> 00:06:16,000
479
+ two different websites.
480
+
481
+ 121
482
+ 00:06:16,000 --> 00:06:21,000
483
+ When your computer go to them, your computer is like, hey, how do I know this is Amazon?
484
+
485
+ 122
486
+ 00:06:21,000 --> 00:06:26,000
487
+ And then you look at your computer, looks at the certificate and say, well, how do I know this is
488
+
489
+ 123
490
+ 00:06:26,000 --> 00:06:26,000
491
+ Amazon?
492
+
493
+ 124
494
+ 00:06:26,000 --> 00:06:31,000
495
+ Well, it's coming from somebody I trust Digicert in particular.
496
+
497
+ 125
498
+ 00:06:31,000 --> 00:06:33,000
499
+ And how do I know this is Amazon?
500
+
501
+ 126
502
+ 00:06:33,000 --> 00:06:43,000
503
+ Because Digicert is saying that this is Amazon and because your computer is able to trust.
504
+
505
+ 127
506
+ 00:06:43,000 --> 00:06:46,000
507
+ Uh digicert you now trust that this is Amazon.
508
+
509
+ 128
510
+ 00:06:46,000 --> 00:06:48,000
511
+ That's how this game works.
512
+
513
+ 129
514
+ 00:06:49,000 --> 00:06:54,000
515
+ There are certain websites where there's something called a self-signed certificate.
516
+
517
+ 130
518
+ 00:06:54,000 --> 00:06:55,000
519
+ We'll talk more about this later.
520
+
521
+ 131
522
+ 00:06:55,000 --> 00:07:00,000
523
+ But self-signed certificates is when the company it's trust it's issued by Amazon to Amazon to Amazon
524
+
525
+ 132
526
+ 00:07:00,000 --> 00:07:01,000
527
+ is saying I'm Amazon.
528
+
529
+ 133
530
+ 00:07:01,000 --> 00:07:04,000
531
+ You don't trust that a lot of people don't trust self-signed certificates.
532
+
533
+ 134
534
+ 00:07:04,000 --> 00:07:08,000
535
+ In fact, when internal organizations do it internally, it's not considered external trust because
536
+
537
+ 135
538
+ 00:07:08,000 --> 00:07:10,000
539
+ nobody trusts it externally.
540
+
541
+ 136
542
+ 00:07:10,000 --> 00:07:11,000
543
+ Self-signed.
544
+
545
+ 137
546
+ 00:07:11,000 --> 00:07:15,000
547
+ That's like me making my own ID it's like, hey, you trust I'm Andrew when I here is an ID that I made
548
+
549
+ 138
550
+ 00:07:15,000 --> 00:07:16,000
551
+ on my computer last time.
552
+
553
+ 139
554
+ 00:07:16,000 --> 00:07:17,000
555
+ It says I'm Andrew.
556
+
557
+ 140
558
+ 00:07:17,000 --> 00:07:18,000
559
+ Do you trust that?
560
+
561
+ 141
562
+ 00:07:18,000 --> 00:07:18,000
563
+ No.
564
+
565
+ 142
566
+ 00:07:18,000 --> 00:07:22,000
567
+ You trust the driver's license because it comes from the DMV.
568
+
569
+ 143
570
+ 00:07:23,000 --> 00:07:25,000
571
+ So that's this concept of trust.
572
+
573
+ 144
574
+ 00:07:25,000 --> 00:07:27,000
575
+ That's why trust is important.
576
+
577
+ 145
578
+ 00:07:27,000 --> 00:07:34,000
579
+ Your computer needs to have some kind of external validation that this is Amazon.
580
+
581
+ 146
582
+ 00:07:34,000 --> 00:07:35,000
583
+ And what's doing that.
584
+
585
+ 147
586
+ 00:07:35,000 --> 00:07:39,000
587
+ The certificate is doing that now a certificate I mentioned.
588
+
589
+ 148
590
+ 00:07:39,000 --> 00:07:39,000
591
+ It's two things.
592
+
593
+ 149
594
+ 00:07:39,000 --> 00:07:46,000
595
+ Not just establishing that trust, but the certificate is a way to give the public key.
596
+
597
+ 150
598
+ 00:07:46,000 --> 00:07:49,000
599
+ And that's important because that's going to become part of this handshake.
600
+
601
+ 151
602
+ 00:07:49,000 --> 00:07:50,000
603
+ And I want to show you guys that.
604
+
605
+ 152
606
+ 00:07:51,000 --> 00:07:57,000
607
+ So by looking if I go to details on this certificate on here.
608
+
609
+ 153
610
+ 00:07:57,000 --> 00:07:59,000
611
+ So this is the Amazon certificate that we have.
612
+
613
+ 154
614
+ 00:07:59,000 --> 00:08:02,000
615
+ And you notice I have a variety of fields here.
616
+
617
+ 155
618
+ 00:08:02,000 --> 00:08:11,000
619
+ So if I go down and I look into all of these fields that is listed here notice subject public key info.
620
+
621
+ 156
622
+ 00:08:12,000 --> 00:08:14,000
623
+ Subjects public key algorithm.
624
+
625
+ 157
626
+ 00:08:14,000 --> 00:08:17,000
627
+ It's an RSA key that they're using.
628
+
629
+ 158
630
+ 00:08:17,000 --> 00:08:19,000
631
+ Remember RSA is asymmetric.
632
+
633
+ 159
634
+ 00:08:19,000 --> 00:08:22,000
635
+ But here is Amazon's actual public key.
636
+
637
+ 160
638
+ 00:08:22,000 --> 00:08:25,000
639
+ This is a it's written it looks weird.
640
+
641
+ 161
642
+ 00:08:25,000 --> 00:08:29,000
643
+ It's written in a hex but it's a 2048 bit RSA key.
644
+
645
+ 162
646
+ 00:08:29,000 --> 00:08:32,000
647
+ This is Amazon's actual public key.
648
+
649
+ 163
650
+ 00:08:33,000 --> 00:08:35,000
651
+ Remember there is a public and a private key.
652
+
653
+ 164
654
+ 00:08:35,000 --> 00:08:41,000
655
+ So Amazon is allowing the transport of their public key to the world.
656
+
657
+ 165
658
+ 00:08:41,000 --> 00:08:47,000
659
+ Now if you remember how asymmetric works in the world of asymmetric cryptography your public key is
660
+
661
+ 166
662
+ 00:08:47,000 --> 00:08:47,000
663
+ given to the world.
664
+
665
+ 167
666
+ 00:08:47,000 --> 00:08:52,000
667
+ The question is how is Amazon distributing the public key to the rest of the world?
668
+
669
+ 168
670
+ 00:08:52,000 --> 00:08:54,000
671
+ Well, that's done using a certificate.
672
+
673
+ 169
674
+ 00:08:54,000 --> 00:08:58,000
675
+ So certificates are ways to pass the public key around.
676
+
677
+ 170
678
+ 00:08:58,000 --> 00:09:00,000
679
+ And that brings me to the SSL handshake.
680
+
681
+ 171
682
+ 00:09:00,000 --> 00:09:06,000
683
+ So exactly when I go to Amazon, what exactly happens in the background.
684
+
685
+ 172
686
+ 00:09:06,000 --> 00:09:09,000
687
+ How am I getting this secure trust between them?
688
+
689
+ 173
690
+ 00:09:09,000 --> 00:09:15,000
691
+ How am I security transferring data and that brings me to the SSL handshake that I have right here.
692
+
693
+ 174
694
+ 00:09:15,000 --> 00:09:18,000
695
+ And again I took this from the IBM website.
696
+
697
+ 175
698
+ 00:09:19,000 --> 00:09:20,000
699
+ Uh.
700
+
701
+ 176
702
+ 00:09:20,000 --> 00:09:25,000
703
+ And the link is provided at the top of me.
704
+
705
+ 177
706
+ 00:09:25,000 --> 00:09:25,000
707
+ All right.
708
+
709
+ 178
710
+ 00:09:25,000 --> 00:09:26,000
711
+ Somewhere around there.
712
+
713
+ 179
714
+ 00:09:27,000 --> 00:09:28,000
715
+ Uh, so let's get into it.
716
+
717
+ 180
718
+ 00:09:28,000 --> 00:09:32,000
719
+ So now the steps are going to be listed on the left side of the screen.
720
+
721
+ 181
722
+ 00:09:32,000 --> 00:09:34,000
723
+ And I want to go over the diagram.
724
+
725
+ 182
726
+ 00:09:34,000 --> 00:09:40,000
727
+ So let's say in this diagram the client is you will put Andy.
728
+
729
+ 183
730
+ 00:09:42,000 --> 00:09:43,000
731
+ And the server is Amazon.
732
+
733
+ 184
734
+ 00:09:46,000 --> 00:09:50,000
735
+ Now I go to Amazon.com and I press enter.
736
+
737
+ 185
738
+ 00:09:50,000 --> 00:09:50,000
739
+ I type.
740
+
741
+ 186
742
+ 00:09:51,000 --> 00:09:51,000
743
+ Well, I don't go.
744
+
745
+ 187
746
+ 00:09:51,000 --> 00:09:54,000
747
+ I type Amazon.com and I press enter.
748
+
749
+ 188
750
+ 00:09:54,000 --> 00:09:55,000
751
+ What happens?
752
+
753
+ 189
754
+ 00:09:55,000 --> 00:09:58,000
755
+ The client issues a secure request session.
756
+
757
+ 190
758
+ 00:09:58,000 --> 00:10:03,000
759
+ So it's me going to Amazon and says, Hey Amazon, I need to set up a secure session with you.
760
+
761
+ 191
762
+ 00:10:03,000 --> 00:10:09,000
763
+ Amazon sends back an X509 certificate.
764
+
765
+ 192
766
+ 00:10:09,000 --> 00:10:11,000
767
+ That's the type of certificate that they're using.
768
+
769
+ 193
770
+ 00:10:11,000 --> 00:10:11,000
771
+ Now.
772
+
773
+ 194
774
+ 00:10:11,000 --> 00:10:14,000
775
+ In reality, almost all certificates are x509.
776
+
777
+ 195
778
+ 00:10:14,000 --> 00:10:16,000
779
+ They send back.
780
+
781
+ 196
782
+ 00:10:16,000 --> 00:10:21,000
783
+ The certificate that I showed you containing their public key.
784
+
785
+ 197
786
+ 00:10:21,000 --> 00:10:24,000
787
+ Now that we spoke about that, I showed you you.
788
+
789
+ 198
790
+ 00:10:24,000 --> 00:10:31,000
791
+ When you receive it, you're going to authenticate that certificate against a list of known certificate
792
+
793
+ 199
794
+ 00:10:31,000 --> 00:10:32,000
795
+ authorities.
796
+
797
+ 200
798
+ 00:10:32,000 --> 00:10:33,000
799
+ This is important.
800
+
801
+ 201
802
+ 00:10:33,000 --> 00:10:35,000
803
+ This is the part of the trust.
804
+
805
+ 202
806
+ 00:10:35,000 --> 00:10:39,000
807
+ So when you receive Amazon Cert, you're like, well, who gave him this cert?
808
+
809
+ 203
810
+ 00:10:39,000 --> 00:10:39,000
811
+ Okay.
812
+
813
+ 204
814
+ 00:10:39,000 --> 00:10:41,000
815
+ It was given by Digicert.
816
+
817
+ 205
818
+ 00:10:41,000 --> 00:10:45,000
819
+ Do you trust Digicert yes I do again your computer does all this.
820
+
821
+ 206
822
+ 00:10:45,000 --> 00:10:49,000
823
+ Your computer trusts Digicert now.
824
+
825
+ 207
826
+ 00:10:49,000 --> 00:10:50,000
827
+ What happened?
828
+
829
+ 208
830
+ 00:10:50,000 --> 00:10:57,000
831
+ You, the client on your computer, generate a symmetric key.
832
+
833
+ 209
834
+ 00:10:58,000 --> 00:11:05,000
835
+ Once you generate the symmetric key, you then encrypt it with the server's public key and you send
836
+
837
+ 210
838
+ 00:11:05,000 --> 00:11:06,000
839
+ it back.
840
+
841
+ 211
842
+ 00:11:06,000 --> 00:11:08,000
843
+ Notice the arrow to Amazon.
844
+
845
+ 212
846
+ 00:11:08,000 --> 00:11:09,000
847
+ So here's what you're doing.
848
+
849
+ 213
850
+ 00:11:09,000 --> 00:11:18,000
851
+ You're going to generate, for example, an AES 120 beta 128 bit or 256 bit AES key.
852
+
853
+ 214
854
+ 00:11:18,000 --> 00:11:21,000
855
+ You're then going to send it to Amazon.com.
856
+
857
+ 215
858
+ 00:11:21,000 --> 00:11:23,000
859
+ Amazon.
860
+
861
+ 216
862
+ 00:11:23,000 --> 00:11:27,000
863
+ Remember it was encrypted with their what public key.
864
+
865
+ 217
866
+ 00:11:27,000 --> 00:11:28,000
867
+ So what does Amazon do.
868
+
869
+ 218
870
+ 00:11:29,000 --> 00:11:32,000
871
+ Amazon once they receive.
872
+
873
+ 219
874
+ 00:11:33,000 --> 00:11:36,000
875
+ Uh, your symmetric key encrypted with their public key.
876
+
877
+ 220
878
+ 00:11:36,000 --> 00:11:38,000
879
+ They decrypt it with their corresponding.
880
+
881
+ 221
882
+ 00:11:38,000 --> 00:11:39,000
883
+ What?
884
+
885
+ 222
886
+ 00:11:39,000 --> 00:11:39,000
887
+ Private key.
888
+
889
+ 223
890
+ 00:11:39,000 --> 00:11:44,000
891
+ Remember, if you encrypt something with Amazon's public key, only Amazon's private key can decrypt
892
+
893
+ 224
894
+ 00:11:44,000 --> 00:11:44,000
895
+ it.
896
+
897
+ 225
898
+ 00:11:45,000 --> 00:11:52,000
899
+ Now Amazon has that public has that symmetric key or that session key that you make.
900
+
901
+ 226
902
+ 00:11:52,000 --> 00:11:55,000
903
+ Now the client and the server knows both.
904
+
905
+ 227
906
+ 00:11:55,000 --> 00:12:02,000
907
+ Now the client and server now both know that symmetric key and the what happens to the rest of it.
908
+
909
+ 228
910
+ 00:12:02,000 --> 00:12:10,000
911
+ Well you Amazon and you and Amazon will now use that symmetric key to encrypt data.
912
+
913
+ 229
914
+ 00:12:10,000 --> 00:12:11,000
915
+ So what happens is this.
916
+
917
+ 230
918
+ 00:12:12,000 --> 00:12:16,000
919
+ You generate a symmetric key, you encrypt it with Amazon's public key.
920
+
921
+ 231
922
+ 00:12:16,000 --> 00:12:19,000
923
+ Remember I showed you the actual public key there.
924
+
925
+ 232
926
+ 00:12:20,000 --> 00:12:22,000
927
+ You encrypt it with that public key.
928
+
929
+ 233
930
+ 00:12:22,000 --> 00:12:23,000
931
+ You send it to Amazon.
932
+
933
+ 234
934
+ 00:12:23,000 --> 00:12:25,000
935
+ Amazon then decrypts it with their private key.
936
+
937
+ 235
938
+ 00:12:26,000 --> 00:12:27,000
939
+ Now they have the symmetric key.
940
+
941
+ 236
942
+ 00:12:27,000 --> 00:12:28,000
943
+ You have the symmetric key.
944
+
945
+ 237
946
+ 00:12:28,000 --> 00:12:36,000
947
+ Anything that you send to Amazon username passwords credit cards address products you want to buy,
948
+
949
+ 238
950
+ 00:12:36,000 --> 00:12:39,000
951
+ search queries, anything that you want to send to Amazon.
952
+
953
+ 239
954
+ 00:12:39,000 --> 00:12:41,000
955
+ You encrypt it with that symmetric key.
956
+
957
+ 240
958
+ 00:12:41,000 --> 00:12:41,000
959
+ Send it to Amazon.
960
+
961
+ 241
962
+ 00:12:41,000 --> 00:12:43,000
963
+ Amazon already has the symmetric key.
964
+
965
+ 242
966
+ 00:12:44,000 --> 00:12:46,000
967
+ Amazon wants to send you back web pages.
968
+
969
+ 243
970
+ 00:12:46,000 --> 00:12:51,000
971
+ They want to send you back product listing confirmations and whatever they encrypt it with that symmetric
972
+
973
+ 244
974
+ 00:12:51,000 --> 00:12:51,000
975
+ key.
976
+
977
+ 245
978
+ 00:12:51,000 --> 00:12:56,000
979
+ Remember symmetric the same key used to encrypt is the same key used to decrypt.
980
+
981
+ 246
982
+ 00:12:56,000 --> 00:13:04,000
983
+ So all of this is happening in the background when you go and when when you go to Amazon and you purchase
984
+
985
+ 247
986
+ 00:13:04,000 --> 00:13:04,000
987
+ anything.
988
+
989
+ 248
990
+ 00:13:05,000 --> 00:13:05,000
991
+ All right.
992
+
993
+ 249
994
+ 00:13:05,000 --> 00:13:08,000
995
+ So that's something that you guys want to keep in mind as you use this.
996
+
997
+ 250
998
+ 00:13:08,000 --> 00:13:15,000
999
+ So if I go back here, if I go back to Amazon, all of what I just mentioned.
1000
+
1001
+ 251
1002
+ 00:13:16,000 --> 00:13:17,000
1003
+ Happens.
1004
+
1005
+ 252
1006
+ 00:13:17,000 --> 00:13:21,000
1007
+ So what if you go to another website?
1008
+
1009
+ 253
1010
+ 00:13:21,000 --> 00:13:21,000
1011
+ All right.
1012
+
1013
+ 254
1014
+ 00:13:21,000 --> 00:13:24,000
1015
+ What if you go to another, uh.
1016
+
1017
+ 255
1018
+ 00:13:26,000 --> 00:13:26,000
1019
+ Website?
1020
+
1021
+ 256
1022
+ 00:13:26,000 --> 00:13:27,000
1023
+ Google.com.
1024
+
1025
+ 257
1026
+ 00:13:27,000 --> 00:13:28,000
1027
+ Let's go to google.com.
1028
+
1029
+ 258
1030
+ 00:13:29,000 --> 00:13:31,000
1031
+ Google.com.
1032
+
1033
+ 259
1034
+ 00:13:31,000 --> 00:13:33,000
1035
+ Everything I just happened just happened.
1036
+
1037
+ 260
1038
+ 00:13:33,000 --> 00:13:35,000
1039
+ Everything I just went through just happened.
1040
+
1041
+ 261
1042
+ 00:13:35,000 --> 00:13:36,000
1043
+ So let's do a quick review.
1044
+
1045
+ 262
1046
+ 00:13:36,000 --> 00:13:37,000
1047
+ What happened?
1048
+
1049
+ 263
1050
+ 00:13:37,000 --> 00:13:40,000
1051
+ When I went to Google, I sent the request to Google.
1052
+
1053
+ 264
1054
+ 00:13:41,000 --> 00:13:43,000
1055
+ Google sent me back their certificate.
1056
+
1057
+ 265
1058
+ 00:13:43,000 --> 00:13:44,000
1059
+ Where is it?
1060
+
1061
+ 266
1062
+ 00:13:44,000 --> 00:13:49,000
1063
+ Well, if I click on the lock icon and I go to connection to secure and I say certificate, this is
1064
+
1065
+ 267
1066
+ 00:13:49,000 --> 00:13:50,000
1067
+ Google certificate.
1068
+
1069
+ 268
1070
+ 00:13:50,000 --> 00:13:55,000
1071
+ By acquiring Google certificate, I acquire Google's public key.
1072
+
1073
+ 269
1074
+ 00:13:56,000 --> 00:13:58,000
1075
+ This is the fingerprint if I go here.
1076
+
1077
+ 270
1078
+ 00:13:59,000 --> 00:14:00,000
1079
+ Whereas Google here we go.
1080
+
1081
+ 271
1082
+ 00:14:00,000 --> 00:14:01,000
1083
+ Google's public key.
1084
+
1085
+ 272
1086
+ 00:14:01,000 --> 00:14:03,000
1087
+ So I acquired a public key.
1088
+
1089
+ 273
1090
+ 00:14:03,000 --> 00:14:05,000
1091
+ What do I do with the public key?
1092
+
1093
+ 274
1094
+ 00:14:05,000 --> 00:14:08,000
1095
+ I generate a symmetric key on my computer.
1096
+
1097
+ 275
1098
+ 00:14:09,000 --> 00:14:15,000
1099
+ I then encrypt that symmetric key with Google's public key send it to Google.
1100
+
1101
+ 276
1102
+ 00:14:15,000 --> 00:14:17,000
1103
+ Google then decrypts it with their private key.
1104
+
1105
+ 277
1106
+ 00:14:17,000 --> 00:14:19,000
1107
+ Now they have the symmetric key.
1108
+
1109
+ 278
1110
+ 00:14:19,000 --> 00:14:20,000
1111
+ I have the symmetric key.
1112
+
1113
+ 279
1114
+ 00:14:20,000 --> 00:14:26,000
1115
+ What Google does is Google then encrypts the web page that I just saw on my screen and sends it to my
1116
+
1117
+ 280
1118
+ 00:14:26,000 --> 00:14:26,000
1119
+ machine.
1120
+
1121
+ 281
1122
+ 00:14:26,000 --> 00:14:31,000
1123
+ When my machine gets it, it decrypts it with symmetric key, all the search queries and all the pages
1124
+
1125
+ 282
1126
+ 00:14:31,000 --> 00:14:36,000
1127
+ that goes back and forth between me and Google is now encrypted with that symmetric key.
1128
+
1129
+ 283
1130
+ 00:14:36,000 --> 00:14:41,000
1131
+ What I just explained to you is the easiest way to understand SSL.
1132
+
1133
+ 284
1134
+ 00:14:41,000 --> 00:14:44,000
1135
+ This is the simplest explanation of it.
1136
+
1137
+ 285
1138
+ 00:14:44,000 --> 00:14:49,000
1139
+ Now it does get technical verification of signatures and all that, but you don't need to know that
1140
+
1141
+ 286
1142
+ 00:14:49,000 --> 00:14:50,000
1143
+ for your exam.
1144
+
1145
+ 287
1146
+ 00:14:50,000 --> 00:14:51,000
1147
+ Understand the SSL handshake.
1148
+
1149
+ 288
1150
+ 00:14:51,000 --> 00:14:55,000
1151
+ And now you see why it's so important to have certificates.
1152
+
1153
+ 289
1154
+ 00:14:55,000 --> 00:15:00,000
1155
+ Because without those certificates, the whole connection wouldn't be able to start.
1156
+
1157
+ 290
1158
+ 00:15:00,000 --> 00:15:01,000
1159
+ There'd be no way of passing that public key.
1160
+
1161
+ 291
1162
+ 00:15:01,000 --> 00:15:06,000
1163
+ There'll be no way to verify that that's Google's public key or Amazon's public key.
1164
+
1165
+ 292
1166
+ 00:15:06,000 --> 00:15:08,000
1167
+ But how do we get a certificate?
1168
+
1169
+ 293
1170
+ 00:15:08,000 --> 00:15:09,000
1171
+ How do we set this thing up?
1172
+
1173
+ 294
1174
+ 00:15:10,000 --> 00:15:12,000
1175
+ Well that we'll cover next.
1176
+
07 - Cryptography/017 PKI Process OB 1.4_en.srt ADDED
@@ -0,0 +1,664 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:00,000
3
+ Okay.
4
+
5
+ 2
6
+ 00:00:00,000 --> 00:00:05,000
7
+ You have just been assigned the job of installing a certificate on a computer.
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:09,000
11
+ Your new your the new system administrator for a company.
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:13,000
15
+ And they said, well, we have a web server that we want to put a certificate on.
16
+
17
+ 5
18
+ 00:00:13,000 --> 00:00:16,000
19
+ What is the process and exactly how is this done?
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:21,000
23
+ So in this video I'm going to walk you guys through the process of how you can get a certificate, a
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:24,000
27
+ trusted certificate on a computer.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:26,000
31
+ Let's get started in this one.
32
+
33
+ 9
34
+ 00:00:26,000 --> 00:00:32,000
35
+ Now, in order to do this, there are basically four components that I need you to know for your exam.
36
+
37
+ 10
38
+ 00:00:32,000 --> 00:00:37,000
39
+ When it comes to getting a certificate, the first thing is that digital certificate.
40
+
41
+ 11
42
+ 00:00:37,000 --> 00:00:40,000
43
+ This is what you want to install on your computer.
44
+
45
+ 12
46
+ 00:00:40,000 --> 00:00:42,000
47
+ If you remember I went over the SSL handshake.
48
+
49
+ 13
50
+ 00:00:43,000 --> 00:00:48,000
51
+ And the SSL handshake begins with the passing of that digital certificate.
52
+
53
+ 14
54
+ 00:00:48,000 --> 00:00:51,000
55
+ So this is a digital document that provides the public key.
56
+
57
+ 15
58
+ 00:00:51,000 --> 00:00:55,000
59
+ It also has a digital signature that provides the trust to the organization.
60
+
61
+ 16
62
+ 00:00:55,000 --> 00:00:58,000
63
+ Where are we going to get the certificates from?
64
+
65
+ 17
66
+ 00:00:58,000 --> 00:01:01,000
67
+ You're going to get that from a certificate authority.
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:07,000
71
+ This is a trusted entity that manages certificates and digitally signs the certificate.
72
+
73
+ 19
74
+ 00:01:07,000 --> 00:01:08,000
75
+ This is the entity.
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:15,000
79
+ This is the DMV, I should say that verifies you are who you say you are.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:23,000
83
+ Now, before the CA can give you a certificate, the CA needs to verify that you're you, that you're
84
+
85
+ 22
86
+ 00:01:23,000 --> 00:01:25,000
87
+ actually that company.
88
+
89
+ 23
90
+ 00:01:25,000 --> 00:01:28,000
91
+ You're not trying to steal someone's identity, that you are Bob Jones.
92
+
93
+ 24
94
+ 00:01:28,000 --> 00:01:30,000
95
+ That's the registration authority.
96
+
97
+ 25
98
+ 00:01:30,000 --> 00:01:31,000
99
+ That's their job.
100
+
101
+ 26
102
+ 00:01:31,000 --> 00:01:38,000
103
+ They're going to verify that the person is who they say they are for the CA before the CA can issue
104
+
105
+ 27
106
+ 00:01:38,000 --> 00:01:38,000
107
+ them a cert.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:45,000
111
+ And when you start to give out your certificate on the internet, you're going to have to get it validated.
112
+
113
+ 29
114
+ 00:01:45,000 --> 00:01:48,000
115
+ People that receive it is going to validate, hey, this certificate is still good.
116
+
117
+ 30
118
+ 00:01:48,000 --> 00:01:51,000
119
+ It's kind of like me giving you my driver's license.
120
+
121
+ 31
122
+ 00:01:51,000 --> 00:01:54,000
123
+ And you're like, well, I don't know.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:01:57,000
127
+ It's this driver's license actually came from the DMV that's still valid.
128
+
129
+ 33
130
+ 00:01:57,000 --> 00:02:02,000
131
+ So you call up a number to check if the license is valid.
132
+
133
+ 34
134
+ 00:02:02,000 --> 00:02:04,000
135
+ That's the validation authority.
136
+
137
+ 35
138
+ 00:02:04,000 --> 00:02:07,000
139
+ Now, I went to Wikipedia and I took their diagram.
140
+
141
+ 36
142
+ 00:02:07,000 --> 00:02:10,000
143
+ I should say I borrowed it the diagram.
144
+
145
+ 37
146
+ 00:02:10,000 --> 00:02:12,000
147
+ But I do have the link right here to it.
148
+
149
+ 38
150
+ 00:02:12,000 --> 00:02:17,000
151
+ So here is the uh all of the information that we need.
152
+
153
+ 39
154
+ 00:02:17,000 --> 00:02:21,000
155
+ Now I'm going to go through it, uh, at a high level right now.
156
+
157
+ 40
158
+ 00:02:21,000 --> 00:02:25,000
159
+ And then we'll take a look at the slides in order to, to go more details into it.
160
+
161
+ 41
162
+ 00:02:25,000 --> 00:02:29,000
163
+ So this is you right here.
164
+
165
+ 42
166
+ 00:02:29,000 --> 00:02:29,000
167
+ This is you.
168
+
169
+ 43
170
+ 00:02:29,000 --> 00:02:35,000
171
+ So the way you start this process is you what what you're going to do.
172
+
173
+ 44
174
+ 00:02:35,000 --> 00:02:36,000
175
+ Let's put you on this.
176
+
177
+ 45
178
+ 00:02:37,000 --> 00:02:42,000
179
+ What you're going to do is you're going to generate the public private key on your machine.
180
+
181
+ 46
182
+ 00:02:42,000 --> 00:02:49,000
183
+ So you have a web server and you're going to create what's called a certificate request certificate,
184
+
185
+ 47
186
+ 00:02:49,000 --> 00:02:52,000
187
+ sign in requests or CSR on your machine.
188
+
189
+ 48
190
+ 00:02:52,000 --> 00:02:56,000
191
+ What this does is that this is going to generate a public and a private key.
192
+
193
+ 49
194
+ 00:02:57,000 --> 00:02:58,000
195
+ On your computer.
196
+
197
+ 50
198
+ 00:02:58,000 --> 00:03:02,000
199
+ The certificate authority does not generate the public private keys.
200
+
201
+ 51
202
+ 00:03:02,000 --> 00:03:04,000
203
+ It signs your public private key.
204
+
205
+ 52
206
+ 00:03:04,000 --> 00:03:08,000
207
+ You generate that public private key pair on your machine.
208
+
209
+ 53
210
+ 00:03:08,000 --> 00:03:09,000
211
+ So you generate.
212
+
213
+ 54
214
+ 00:03:09,000 --> 00:03:12,000
215
+ This is going to be your private key.
216
+
217
+ 55
218
+ 00:03:13,000 --> 00:03:15,000
219
+ And you generate your public key.
220
+
221
+ 56
222
+ 00:03:15,000 --> 00:03:21,000
223
+ What you do now is you then take this and you submit it to a registration authority.
224
+
225
+ 57
226
+ 00:03:21,000 --> 00:03:29,000
227
+ Now, the registration authority is the entity that verifies that you are who you say you are.
228
+
229
+ 58
230
+ 00:03:29,000 --> 00:03:36,000
231
+ For example, let's say you are a hacker and you want to reproduce Amazon.com.
232
+
233
+ 59
234
+ 00:03:36,000 --> 00:03:41,000
235
+ Well, you just can't go and get a certificate with the name Amazon.com because you're going to have
236
+
237
+ 60
238
+ 00:03:41,000 --> 00:03:43,000
239
+ to prove that you are Amazon.
240
+
241
+ 61
242
+ 00:03:43,000 --> 00:03:50,000
243
+ If you are organization A or B or C, and you want to get a certificate for that organization, you're
244
+
245
+ 62
246
+ 00:03:50,000 --> 00:03:54,000
247
+ going to have to verify that you are that company and depend how it's done.
248
+
249
+ 63
250
+ 00:03:54,000 --> 00:03:58,000
251
+ It may just be checking the domain actually belongs to you, or it may be that they're going to check
252
+
253
+ 64
254
+ 00:03:58,000 --> 00:04:00,000
255
+ that the company actually exists.
256
+
257
+ 65
258
+ 00:04:00,000 --> 00:04:03,000
259
+ That's the registration authority.
260
+
261
+ 66
262
+ 00:04:03,000 --> 00:04:06,000
263
+ So the registration authority stamps that OKC okay.
264
+
265
+ 67
266
+ 00:04:06,000 --> 00:04:08,000
267
+ This is Bob.
268
+
269
+ 68
270
+ 00:04:08,000 --> 00:04:10,000
271
+ This is company A this is what.
272
+
273
+ 69
274
+ 00:04:10,000 --> 00:04:12,000
275
+ And you can trust them.
276
+
277
+ 70
278
+ 00:04:12,000 --> 00:04:16,000
279
+ The registration authority then sends your public key.
280
+
281
+ 71
282
+ 00:04:16,000 --> 00:04:17,000
283
+ To the CA.
284
+
285
+ 72
286
+ 00:04:17,000 --> 00:04:26,000
287
+ The CA then takes all of your company information, all this great stuff that was given to them, including
288
+
289
+ 73
290
+ 00:04:26,000 --> 00:04:32,000
291
+ your public key and what the CA does is it then sends you back a certificate.
292
+
293
+ 74
294
+ 00:04:32,000 --> 00:04:39,000
295
+ Now on the certificate it contains your public key, but it also contains a digital signature from the
296
+
297
+ 75
298
+ 00:04:39,000 --> 00:04:39,000
299
+ CA.
300
+
301
+ 76
302
+ 00:04:40,000 --> 00:04:45,000
303
+ Now if you remember what a digital signature is, a digital signature verifies that something actually
304
+
305
+ 77
306
+ 00:04:45,000 --> 00:04:48,000
307
+ came from that entity and it was never modified.
308
+
309
+ 78
310
+ 00:04:48,000 --> 00:04:58,000
311
+ So when you receive this certificate and you install it on your web server, this certificate was never
312
+
313
+ 79
314
+ 00:04:58,000 --> 00:05:00,000
315
+ actually issued by you, was it?
316
+
317
+ 80
318
+ 00:05:00,000 --> 00:05:01,000
319
+ It came from who?
320
+
321
+ 81
322
+ 00:05:01,000 --> 00:05:02,000
323
+ The certificate authority.
324
+
325
+ 82
326
+ 00:05:02,000 --> 00:05:06,000
327
+ The only thing it has that you really gave it was basically a public key.
328
+
329
+ 83
330
+ 00:05:06,000 --> 00:05:08,000
331
+ But the certificate has more information.
332
+
333
+ 84
334
+ 00:05:08,000 --> 00:05:12,000
335
+ I have a video coming up later on all the other data that the certificate contains.
336
+
337
+ 85
338
+ 00:05:12,000 --> 00:05:18,000
339
+ So what you do is you install that certificate on your machine.
340
+
341
+ 86
342
+ 00:05:18,000 --> 00:05:20,000
343
+ Now you're done with these entities.
344
+
345
+ 87
346
+ 00:05:20,000 --> 00:05:27,000
347
+ Now somebody comes to Shop.com or whatever your website is, and the first thing you're going to do,
348
+
349
+ 88
350
+ 00:05:27,000 --> 00:05:32,000
351
+ if you remember the SSL handshake is you're going to do what you're going to send them that certificate
352
+
353
+ 89
354
+ 00:05:32,000 --> 00:05:35,000
355
+ so you can start the SSL connection.
356
+
357
+ 90
358
+ 00:05:35,000 --> 00:05:36,000
359
+ You send them the certificate.
360
+
361
+ 91
362
+ 00:05:36,000 --> 00:05:38,000
363
+ Well, how do they know the certificate is still valid?
364
+
365
+ 92
366
+ 00:05:38,000 --> 00:05:42,000
367
+ How do they know your website hasn't been hacked or something went wrong?
368
+
369
+ 93
370
+ 00:05:42,000 --> 00:05:47,000
371
+ You didn't renew the certificate, you became malicious and your company is stealing data now.
372
+
373
+ 94
374
+ 00:05:48,000 --> 00:05:52,000
375
+ Well, what they do is they send their certificate to a validation authority.
376
+
377
+ 95
378
+ 00:05:52,000 --> 00:05:57,000
379
+ Now notice the CA also sent information to the validation authority.
380
+
381
+ 96
382
+ 00:05:57,000 --> 00:05:59,000
383
+ To day I issue this cert.
384
+
385
+ 97
386
+ 00:05:59,000 --> 00:06:05,000
387
+ And if anybody ever wants to check if it's good just let them know it's okay because we did issue that.
388
+
389
+ 98
390
+ 00:06:06,000 --> 00:06:12,000
391
+ The validation authority when they when the user gets it, checks it and says okay it's good.
392
+
393
+ 99
394
+ 00:06:12,000 --> 00:06:14,000
395
+ Tells back to use a yeah, this is good.
396
+
397
+ 100
398
+ 00:06:14,000 --> 00:06:14,000
399
+ You can use it.
400
+
401
+ 101
402
+ 00:06:14,000 --> 00:06:17,000
403
+ And this starts the entire SSL connection.
404
+
405
+ 102
406
+ 00:06:18,000 --> 00:06:24,000
407
+ So this is the PKI process in a nutshell with a CA, an RA and a VA.
408
+
409
+ 103
410
+ 00:06:24,000 --> 00:06:33,000
411
+ Now I just want to point out something that even though in this particular diagram it looks like it's
412
+
413
+ 104
414
+ 00:06:33,000 --> 00:06:34,000
415
+ different entities.
416
+
417
+ 105
418
+ 00:06:34,000 --> 00:06:37,000
419
+ RA it's all the same entity.
420
+
421
+ 106
422
+ 00:06:37,000 --> 00:06:39,000
423
+ Generally this like Digicert.
424
+
425
+ 107
426
+ 00:06:40,000 --> 00:06:44,000
427
+ Uh, GoDaddy or whoever you're using as your public key.
428
+
429
+ 108
430
+ 00:06:44,000 --> 00:06:45,000
431
+ It's always the same entity.
432
+
433
+ 109
434
+ 00:06:45,000 --> 00:06:48,000
435
+ It's not going to be like it's three different businesses.
436
+
437
+ 110
438
+ 00:06:48,000 --> 00:06:56,000
439
+ But in organizations that utilizes internal certs, they can have different machines to do this particular
440
+
441
+ 111
442
+ 00:06:56,000 --> 00:06:57,000
443
+ job.
444
+
445
+ 112
446
+ 00:06:57,000 --> 00:07:00,000
447
+ Now let's take a look at some things here.
448
+
449
+ 113
450
+ 00:07:00,000 --> 00:07:04,000
451
+ Now everything I covered is in detail on these two sections.
452
+
453
+ 114
454
+ 00:07:04,000 --> 00:07:06,000
455
+ So I'm going to go over them quickly since we covered it already.
456
+
457
+ 115
458
+ 00:07:06,000 --> 00:07:09,000
459
+ So the certificate signing request.
460
+
461
+ 116
462
+ 00:07:09,000 --> 00:07:13,000
463
+ So this is the part of it where we had to.
464
+
465
+ 117
466
+ 00:07:14,000 --> 00:07:15,000
467
+ Obtain.
468
+
469
+ 118
470
+ 00:07:15,000 --> 00:07:19,000
471
+ This is the request we're going to send to the CA to get that digital certificate.
472
+
473
+ 119
474
+ 00:07:19,000 --> 00:07:19,000
475
+ All right.
476
+
477
+ 120
478
+ 00:07:19,000 --> 00:07:24,000
479
+ So the first thing we're going to be doing is in order to do this, we're going to have to include things
480
+
481
+ 121
482
+ 00:07:24,000 --> 00:07:29,000
483
+ like our organization name, our domain name, what country we're in, and of course our public key.
484
+
485
+ 122
486
+ 00:07:29,000 --> 00:07:31,000
487
+ So this is what we're sending.
488
+
489
+ 123
490
+ 00:07:31,000 --> 00:07:35,000
491
+ Now the first thing you want to do is you want to start this process.
492
+
493
+ 124
494
+ 00:07:35,000 --> 00:07:41,000
495
+ When you want to get a certificate is you have to go to your machine and you have to create a key pair,
496
+
497
+ 125
498
+ 00:07:41,000 --> 00:07:43,000
499
+ that public private key pair.
500
+
501
+ 126
502
+ 00:07:43,000 --> 00:07:44,000
503
+ Remember the private key is kept secret.
504
+
505
+ 127
506
+ 00:07:44,000 --> 00:07:46,000
507
+ The public key is given to anyone.
508
+
509
+ 128
510
+ 00:07:46,000 --> 00:07:48,000
511
+ You want to fill in the details.
512
+
513
+ 129
514
+ 00:07:48,000 --> 00:07:49,000
515
+ All right.
516
+
517
+ 130
518
+ 00:07:49,000 --> 00:07:52,000
519
+ The certificate is going to have a is going to need a lot of information.
520
+
521
+ 131
522
+ 00:07:52,000 --> 00:07:55,000
523
+ All this information the name of your company where it's located state.
524
+
525
+ 132
526
+ 00:07:55,000 --> 00:07:58,000
527
+ And I'm going to show you certificate details in the next video.
528
+
529
+ 133
530
+ 00:07:58,000 --> 00:08:01,000
531
+ And you're going to see a certificate has all this information.
532
+
533
+ 134
534
+ 00:08:02,000 --> 00:08:08,000
535
+ So you create this, uh, you create it using a software.
536
+
537
+ 135
538
+ 00:08:08,000 --> 00:08:14,000
539
+ And this is going to be submitted in a format that the CAS can understand that format.
540
+
541
+ 136
542
+ 00:08:14,000 --> 00:08:18,000
543
+ But I get into technical is called PK, CS number ten.
544
+
545
+ 137
546
+ 00:08:18,000 --> 00:08:21,000
547
+ This is the format that it's submitted into.
548
+
549
+ 138
550
+ 00:08:21,000 --> 00:08:27,000
551
+ This is just a file format, if you think about it like an Excel file as dot xls x.
552
+
553
+ 139
554
+ 00:08:27,000 --> 00:08:28,000
555
+ That's the file format.
556
+
557
+ 140
558
+ 00:08:28,000 --> 00:08:29,000
559
+ This is just the file format.
560
+
561
+ 141
562
+ 00:08:29,000 --> 00:08:30,000
563
+ What does it contain?
564
+
565
+ 142
566
+ 00:08:30,000 --> 00:08:33,000
567
+ Well, the public key and all the corresponding information.
568
+
569
+ 143
570
+ 00:08:34,000 --> 00:08:38,000
571
+ Now you submit the CSR to the RA to the CA.
572
+
573
+ 144
574
+ 00:08:38,000 --> 00:08:39,000
575
+ What happens here?
576
+
577
+ 145
578
+ 00:08:40,000 --> 00:08:43,000
579
+ Uh, they will validate your identity.
580
+
581
+ 146
582
+ 00:08:43,000 --> 00:08:44,000
583
+ They'll validate that you're good.
584
+
585
+ 147
586
+ 00:08:45,000 --> 00:08:50,000
587
+ And once they can validate all that information, we'll talk more about validations coming up a little
588
+
589
+ 148
590
+ 00:08:50,000 --> 00:08:51,000
591
+ bit later.
592
+
593
+ 149
594
+ 00:08:51,000 --> 00:08:53,000
595
+ But they're going to validate that you're good.
596
+
597
+ 150
598
+ 00:08:53,000 --> 00:08:58,000
599
+ Sometimes they may validate your just your domain name or sometimes they'll do an extended validation.
600
+
601
+ 151
602
+ 00:08:58,000 --> 00:09:03,000
603
+ We're going to do more than a domain name that you actually own that domain, but you actually own that
604
+
605
+ 152
606
+ 00:09:03,000 --> 00:09:04,000
607
+ business.
608
+
609
+ 153
610
+ 00:09:04,000 --> 00:09:06,000
611
+ Then the certificate is issued to you.
612
+
613
+ 154
614
+ 00:09:06,000 --> 00:09:12,000
615
+ You install it on your web server, and you're ready to rock and roll with the SSL connection.
616
+
617
+ 155
618
+ 00:09:12,000 --> 00:09:12,000
619
+ Okay.
620
+
621
+ 156
622
+ 00:09:12,000 --> 00:09:16,000
623
+ So that's the process of how to get a certificate.
624
+
625
+ 157
626
+ 00:09:17,000 --> 00:09:24,000
627
+ Now I want you guys to keep in mind that this is a very easy and simple process.
628
+
629
+ 158
630
+ 00:09:24,000 --> 00:09:28,000
631
+ It's if you've ever installed a certificate on a web server, it's a very simple thing.
632
+
633
+ 159
634
+ 00:09:28,000 --> 00:09:33,000
635
+ You go to the web server, you do a few clicks that give you doing an IIs server, and you create that
636
+
637
+ 160
638
+ 00:09:33,000 --> 00:09:34,000
639
+ certificate request.
640
+
641
+ 161
642
+ 00:09:34,000 --> 00:09:38,000
643
+ You go to your CA, you basically install it there and they give you a certificate.
644
+
645
+ 162
646
+ 00:09:38,000 --> 00:09:39,000
647
+ You put it back on your web server.
648
+
649
+ 163
650
+ 00:09:39,000 --> 00:09:44,000
651
+ There's something that's done actually doesn't take very long, a few minutes if you know the skills
652
+
653
+ 164
654
+ 00:09:44,000 --> 00:09:44,000
655
+ to do it.
656
+
657
+ 165
658
+ 00:09:44,000 --> 00:09:46,000
659
+ So it's not complex to do.
660
+
661
+ 166
662
+ 00:09:46,000 --> 00:09:50,000
663
+ But for your exam you want to be able to understand the process, which is what we just went over.
664
+
07 - Cryptography/018 Certificates OB 1.4_en.srt ADDED
@@ -0,0 +1,824 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:02,000
3
+ In this video we're going to be talking about certificates.
4
+
5
+ 2
6
+ 00:00:02,000 --> 00:00:05,000
7
+ What exactly is on a certificate?
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:07,000
11
+ Now, I already went over that.
12
+
13
+ 4
14
+ 00:00:07,000 --> 00:00:11,000
15
+ It has the signature from the, uh, certificate authority.
16
+
17
+ 5
18
+ 00:00:12,000 --> 00:00:13,000
19
+ It also has your public key.
20
+
21
+ 6
22
+ 00:00:13,000 --> 00:00:14,000
23
+ But what else does it contain?
24
+
25
+ 7
26
+ 00:00:14,000 --> 00:00:16,000
27
+ Let's get into that.
28
+
29
+ 8
30
+ 00:00:16,000 --> 00:00:17,000
31
+ I want to talk about the format.
32
+
33
+ 9
34
+ 00:00:17,000 --> 00:00:20,000
35
+ Self-signed certificates versus third party certificates.
36
+
37
+ 10
38
+ 00:00:20,000 --> 00:00:21,000
39
+ Let's knock it out.
40
+
41
+ 11
42
+ 00:00:21,000 --> 00:00:26,000
43
+ The first thing I want to do is I want to show you guys when you have a certificate.
44
+
45
+ 12
46
+ 00:00:27,000 --> 00:00:29,000
47
+ Now, a certificate has a variety of different fields.
48
+
49
+ 13
50
+ 00:00:29,000 --> 00:00:31,000
51
+ It's not just the couple things.
52
+
53
+ 14
54
+ 00:00:31,000 --> 00:00:35,000
55
+ In fact, it has a couple different things on it, from a version number to the subject's name, the
56
+
57
+ 15
58
+ 00:00:35,000 --> 00:00:38,000
59
+ company's name, your public key.
60
+
61
+ 16
62
+ 00:00:38,000 --> 00:00:43,000
63
+ Who gave you the certificate, how long it's valid for, what digital signature algorithm you're using,
64
+
65
+ 17
66
+ 00:00:43,000 --> 00:00:47,000
67
+ and a unique serial number to identify the certificate.
68
+
69
+ 18
70
+ 00:00:47,000 --> 00:00:48,000
71
+ You know the certificate types.
72
+
73
+ 19
74
+ 00:00:48,000 --> 00:00:53,000
75
+ Now, I do want to mention this, that all certificates that are coming out today is going to be the
76
+
77
+ 20
78
+ 00:00:53,000 --> 00:00:55,000
79
+ X509 certificate.
80
+
81
+ 21
82
+ 00:00:55,000 --> 00:00:57,000
83
+ It's going to be a certificate format.
84
+
85
+ 22
86
+ 00:00:57,000 --> 00:01:02,000
87
+ Now the certificate types are going to be either it's going to be self-signed or it's going to be third
88
+
89
+ 23
90
+ 00:01:02,000 --> 00:01:04,000
91
+ party issue, which we'll take a look at in a few minutes.
92
+
93
+ 24
94
+ 00:01:04,000 --> 00:01:14,000
95
+ So I want to show you all of these fields on an actual certificate so you can better understand what
96
+
97
+ 25
98
+ 00:01:14,000 --> 00:01:14,000
99
+ I'm talking about.
100
+
101
+ 26
102
+ 00:01:14,000 --> 00:01:16,000
103
+ So let's go to Amazon.com.
104
+
105
+ 27
106
+ 00:01:16,000 --> 00:01:17,000
107
+ Here we are back again.
108
+
109
+ 28
110
+ 00:01:18,000 --> 00:01:19,000
111
+ Connection is secure.
112
+
113
+ 29
114
+ 00:01:19,000 --> 00:01:22,000
115
+ Let's take a look at some of the things I mentioned.
116
+
117
+ 30
118
+ 00:01:22,000 --> 00:01:23,000
119
+ So we're going to go to detail.
120
+
121
+ 31
122
+ 00:01:23,000 --> 00:01:25,000
123
+ So we have all the data.
124
+
125
+ 32
126
+ 00:01:25,000 --> 00:01:29,000
127
+ So right now I'm just going to expand some of these boxes so you can see them.
128
+
129
+ 33
130
+ 00:01:30,000 --> 00:01:32,000
131
+ Uh first of all what version is it.
132
+
133
+ 34
134
+ 00:01:32,000 --> 00:01:34,000
135
+ Well this is version three certificate.
136
+
137
+ 35
138
+ 00:01:34,000 --> 00:01:35,000
139
+ Here is a serial number.
140
+
141
+ 36
142
+ 00:01:35,000 --> 00:01:38,000
143
+ Now this is a unique number that is unique to this certificate.
144
+
145
+ 37
146
+ 00:01:38,000 --> 00:01:40,000
147
+ No certificate should have this.
148
+
149
+ 38
150
+ 00:01:40,000 --> 00:01:42,000
151
+ The signature algorithm.
152
+
153
+ 39
154
+ 00:01:43,000 --> 00:01:49,000
155
+ Now, I mentioned that a digital signature using the DSS standards is generally some kind of asymmetric
156
+
157
+ 40
158
+ 00:01:49,000 --> 00:01:51,000
159
+ algorithm and a hashing algorithm.
160
+
161
+ 41
162
+ 00:01:51,000 --> 00:01:56,000
163
+ In this one, we're going to be using Sha 256 with RSA.
164
+
165
+ 42
166
+ 00:01:56,000 --> 00:01:58,000
167
+ Pretty pretty standard.
168
+
169
+ 43
170
+ 00:01:58,000 --> 00:02:00,000
171
+ Who gave us the certificate.
172
+
173
+ 44
174
+ 00:02:00,000 --> 00:02:04,000
175
+ Now Digicert is one of the biggest provider of certificate.
176
+
177
+ 45
178
+ 00:02:04,000 --> 00:02:08,000
179
+ Digicert took over from Symantec's who took over VeriSign.
180
+
181
+ 46
182
+ 00:02:08,000 --> 00:02:11,000
183
+ VeriSign being one of the most popular names out there.
184
+
185
+ 47
186
+ 00:02:11,000 --> 00:02:16,000
187
+ But Digicert is now them, and there's a lot of big names in this space.
188
+
189
+ 48
190
+ 00:02:16,000 --> 00:02:17,000
191
+ Uh, such as?
192
+
193
+ 49
194
+ 00:02:18,000 --> 00:02:23,000
195
+ I know GoDaddy gives out a lot of certificates, you can get Google search and so on.
196
+
197
+ 50
198
+ 00:02:23,000 --> 00:02:24,000
199
+ How long is it valid?
200
+
201
+ 51
202
+ 00:02:24,000 --> 00:02:24,000
203
+ What?
204
+
205
+ 52
206
+ 00:02:24,000 --> 00:02:26,000
207
+ A certificate is not valid forever.
208
+
209
+ 53
210
+ 00:02:26,000 --> 00:02:31,000
211
+ In fact, you have to renew certificates generally every 1 to 3 years.
212
+
213
+ 54
214
+ 00:02:31,000 --> 00:02:41,000
215
+ You notice, uh, this particular certificate is valid basically from 1127 23 to 11 1124.
216
+
217
+ 55
218
+ 00:02:41,000 --> 00:02:46,000
219
+ So this is about a one year, a little less than a one year certificate.
220
+
221
+ 56
222
+ 00:02:46,000 --> 00:02:54,000
223
+ The subject, well, the chronological or the key name, this certificate is only for WW dot amazon.com.
224
+
225
+ 57
226
+ 00:02:54,000 --> 00:02:58,000
227
+ So this is certificate can only be used at WW dot.
228
+
229
+ 58
230
+ 00:02:58,000 --> 00:03:01,000
231
+ So this is going to be a certificate only for this website.
232
+
233
+ 59
234
+ 00:03:01,000 --> 00:03:03,000
235
+ But who exactly.
236
+
237
+ 60
238
+ 00:03:04,000 --> 00:03:05,000
239
+ I'm.
240
+
241
+ 61
242
+ 00:03:05,000 --> 00:03:06,000
243
+ So where is the public key on this.
244
+
245
+ 62
246
+ 00:03:06,000 --> 00:03:08,000
247
+ So the subject's public key.
248
+
249
+ 63
250
+ 00:03:08,000 --> 00:03:09,000
251
+ So we have.
252
+
253
+ 64
254
+ 00:03:10,000 --> 00:03:12,000
255
+ The the public key algorithm.
256
+
257
+ 65
258
+ 00:03:12,000 --> 00:03:13,000
259
+ It's an RSA key.
260
+
261
+ 66
262
+ 00:03:13,000 --> 00:03:15,000
263
+ Here is the public key.
264
+
265
+ 67
266
+ 00:03:15,000 --> 00:03:19,000
267
+ Now in here there are some additional things I don't.
268
+
269
+ 68
270
+ 00:03:19,000 --> 00:03:23,000
271
+ You don't need to go into all of these things such as certificate policies and all that.
272
+
273
+ 69
274
+ 00:03:23,000 --> 00:03:29,000
275
+ But what I do need you guys to know is there is something we call a CRL distribution point, certificate
276
+
277
+ 70
278
+ 00:03:29,000 --> 00:03:35,000
279
+ revocation list distribution point, which you can find on the certificate itself to check if the certificate
280
+
281
+ 71
282
+ 00:03:35,000 --> 00:03:37,000
283
+ has been revoked.
284
+
285
+ 72
286
+ 00:03:37,000 --> 00:03:40,000
287
+ That is something we're going to cover a little bit later.
288
+
289
+ 73
290
+ 00:03:41,000 --> 00:03:45,000
291
+ If I just take a look at the general part of the certificate, you can see it's just giving me some
292
+
293
+ 74
294
+ 00:03:45,000 --> 00:03:50,000
295
+ of the basic information that I had their start on expires on.
296
+
297
+ 75
298
+ 00:03:50,000 --> 00:03:57,000
299
+ So this is going to be some of the main fields that you should understand about a certificate.
300
+
301
+ 76
302
+ 00:03:58,000 --> 00:04:02,000
303
+ Now when you get a certificate let's go back to slides here.
304
+
305
+ 77
306
+ 00:04:02,000 --> 00:04:03,000
307
+ Oops.
308
+
309
+ 78
310
+ 00:04:04,000 --> 00:04:05,000
311
+ Uh, there's a couple of things here.
312
+
313
+ 79
314
+ 00:04:06,000 --> 00:04:12,000
315
+ When you get a certificate, there's what's called an entity certificate, what's called a domain validation
316
+
317
+ 80
318
+ 00:04:12,000 --> 00:04:14,000
319
+ certificate and extended validation.
320
+
321
+ 81
322
+ 00:04:14,000 --> 00:04:20,000
323
+ When you go out and you purchase a certificate from somebody like Digicert, a domain validation just
324
+
325
+ 82
326
+ 00:04:20,000 --> 00:04:26,000
327
+ checks if you actually own the domain Amazon.com, but it doesn't verify if that business is associated
328
+
329
+ 83
330
+ 00:04:26,000 --> 00:04:27,000
331
+ with that domain.
332
+
333
+ 84
334
+ 00:04:27,000 --> 00:04:30,000
335
+ That's going to be called an extended validation.
336
+
337
+ 85
338
+ 00:04:30,000 --> 00:04:36,000
339
+ Sometimes if you go to a website and the the bar at the top turns green, that's an extended validation
340
+
341
+ 86
342
+ 00:04:36,000 --> 00:04:37,000
343
+ certificate.
344
+
345
+ 87
346
+ 00:04:37,000 --> 00:04:41,000
347
+ Another type of certificate you can get is what's called a wild card certificate.
348
+
349
+ 88
350
+ 00:04:41,000 --> 00:04:44,000
351
+ So wild card certificates if you notice it has a wild card.
352
+
353
+ 89
354
+ 00:04:44,000 --> 00:04:49,000
355
+ If you remember the one on Amazon was just WW dot amazon.com.
356
+
357
+ 90
358
+ 00:04:50,000 --> 00:04:53,000
359
+ That can't be used for anything but that w w dot.
360
+
361
+ 91
362
+ 00:04:53,000 --> 00:04:59,000
363
+ If you go and you get a wildcard certificate with a wildcard, you notice how I have this wildcard at
364
+
365
+ 92
366
+ 00:04:59,000 --> 00:05:00,000
367
+ Tidcombe.
368
+
369
+ 93
370
+ 00:05:00,000 --> 00:05:05,000
371
+ So we could use it for t w w dot t edu comm.
372
+
373
+ 94
374
+ 00:05:05,000 --> 00:05:07,000
375
+ You can use it for mail at tidcombe.
376
+
377
+ 95
378
+ 00:05:07,000 --> 00:05:13,000
379
+ We can use it maybe for if you had a subdomain called vpn at t com ftp at tidcombe.
380
+
381
+ 96
382
+ 00:05:13,000 --> 00:05:17,000
383
+ So you can use it for multiple subdomains.
384
+
385
+ 97
386
+ 00:05:17,000 --> 00:05:26,000
387
+ Now I do want to talk about when you get a certificate, you can get them either from yourself or you
388
+
389
+ 98
390
+ 00:05:26,000 --> 00:05:29,000
391
+ can get them from a certificate authority like Digicert.
392
+
393
+ 99
394
+ 00:05:30,000 --> 00:05:34,000
395
+ And there are many, like I said, Digicert GoDaddy.
396
+
397
+ 100
398
+ 00:05:34,000 --> 00:05:37,000
399
+ I use a site called cheap SSL.
400
+
401
+ 101
402
+ 00:05:37,000 --> 00:05:40,000
403
+ Uh, so there is a ton of them.
404
+
405
+ 102
406
+ 00:05:40,000 --> 00:05:42,000
407
+ I'm not going to get into all the different names.
408
+
409
+ 103
410
+ 00:05:42,000 --> 00:05:43,000
411
+ It's out of the scope here.
412
+
413
+ 104
414
+ 00:05:43,000 --> 00:05:49,000
415
+ But if you just go to Google and you type, uh, SSL certificates or purchase certificates, you know
416
+
417
+ 105
418
+ 00:05:49,000 --> 00:05:51,000
419
+ what I'll do that when I get here so I can show you some of the names here.
420
+
421
+ 106
422
+ 00:05:51,000 --> 00:05:52,000
423
+ Okay.
424
+
425
+ 107
426
+ 00:05:52,000 --> 00:05:53,000
427
+ But let's go.
428
+
429
+ 108
430
+ 00:05:53,000 --> 00:05:59,000
431
+ Self-signed certificates A self-signed certificate is a certificate that you make internally in your
432
+
433
+ 109
434
+ 00:05:59,000 --> 00:06:01,000
435
+ organization.
436
+
437
+ 110
438
+ 00:06:01,000 --> 00:06:05,000
439
+ The problem with a self-signed certificate is the trust level.
440
+
441
+ 111
442
+ 00:06:05,000 --> 00:06:10,000
443
+ Okay, so this is something that you make internally, and it has no independence of trust.
444
+
445
+ 112
446
+ 00:06:10,000 --> 00:06:12,000
447
+ In other words, only you trust it.
448
+
449
+ 113
450
+ 00:06:12,000 --> 00:06:15,000
451
+ Only your organization trusts it.
452
+
453
+ 114
454
+ 00:06:15,000 --> 00:06:18,000
455
+ Now, you're probably saying yourself, well, is it useful?
456
+
457
+ 115
458
+ 00:06:18,000 --> 00:06:27,000
459
+ Well, it's it's useful as much, externally speaking, as an ID that you make inside.
460
+
461
+ 116
462
+ 00:06:28,000 --> 00:06:28,000
463
+ Okay.
464
+
465
+ 117
466
+ 00:06:28,000 --> 00:06:28,000
467
+ Think about this.
468
+
469
+ 118
470
+ 00:06:28,000 --> 00:06:34,000
471
+ If you are a company and you create badges for all your employees.
472
+
473
+ 119
474
+ 00:06:35,000 --> 00:06:41,000
475
+ Those employees can't use your company badges or IDs to externally validate anything externally.
476
+
477
+ 120
478
+ 00:06:41,000 --> 00:06:44,000
479
+ They can't give it to highway patrol and says, this is me, right?
480
+
481
+ 121
482
+ 00:06:44,000 --> 00:06:48,000
483
+ Nobody's going to know what kind of stupid ID is this?
484
+
485
+ 122
486
+ 00:06:48,000 --> 00:06:49,000
487
+ We don't trust this.
488
+
489
+ 123
490
+ 00:06:49,000 --> 00:06:52,000
491
+ But people in your organization will.
492
+
493
+ 124
494
+ 00:06:52,000 --> 00:07:02,000
495
+ So if you want to set up SSL connection within your organization, that is okay because it's all trusted
496
+
497
+ 125
498
+ 00:07:02,000 --> 00:07:04,000
499
+ internally, but you need that SSL connection.
500
+
501
+ 126
502
+ 00:07:04,000 --> 00:07:07,000
503
+ Then I recommend a self-signed certificate.
504
+
505
+ 127
506
+ 00:07:07,000 --> 00:07:08,000
507
+ The cost is free.
508
+
509
+ 128
510
+ 00:07:08,000 --> 00:07:09,000
511
+ That's what makes it good.
512
+
513
+ 129
514
+ 00:07:09,000 --> 00:07:13,000
515
+ It's actually free versus Digicert can cost a couple GS a year.
516
+
517
+ 130
518
+ 00:07:14,000 --> 00:07:15,000
519
+ A couple of thousand dollars.
520
+
521
+ 131
522
+ 00:07:15,000 --> 00:07:19,000
523
+ So the use case here is going to be for internal networks applications.
524
+
525
+ 132
526
+ 00:07:19,000 --> 00:07:26,000
527
+ If you need to issue certificates for smart cards, people log in internal SSL on web servers, internally
528
+
529
+ 133
530
+ 00:07:26,000 --> 00:07:29,000
531
+ speaking, where it never touches the external world.
532
+
533
+ 134
534
+ 00:07:30,000 --> 00:07:32,000
535
+ This is a good solution.
536
+
537
+ 135
538
+ 00:07:32,000 --> 00:07:35,000
539
+ It's free and you should be doing this.
540
+
541
+ 136
542
+ 00:07:35,000 --> 00:07:36,000
543
+ I.
544
+
545
+ 137
546
+ 00:07:36,000 --> 00:07:41,000
547
+ In fact at TI we have a ton of self-signed certificates on all of our internal servers now.
548
+
549
+ 138
550
+ 00:07:42,000 --> 00:07:48,000
551
+ If what you're doing is going to be external facing and you need that external validation, you need
552
+
553
+ 139
554
+ 00:07:48,000 --> 00:07:56,000
555
+ that DMV, I should say to validate your request, then you can go and get a third party certificate.
556
+
557
+ 140
558
+ 00:07:56,000 --> 00:07:58,000
559
+ And before I get into this, you know what?
560
+
561
+ 141
562
+ 00:07:58,000 --> 00:08:00,000
563
+ Let me just show it to you.
564
+
565
+ 142
566
+ 00:08:01,000 --> 00:08:02,000
567
+ Uh, all the different.
568
+
569
+ 143
570
+ 00:08:04,000 --> 00:08:09,000
571
+ So I'm going to go to Google and I am going to say.
572
+
573
+ 144
574
+ 00:08:11,000 --> 00:08:12,000
575
+ Where is my, uh.
576
+
577
+ 145
578
+ 00:08:12,000 --> 00:08:12,000
579
+ Here we go.
580
+
581
+ 146
582
+ 00:08:12,000 --> 00:08:12,000
583
+ Oh.
584
+
585
+ 147
586
+ 00:08:12,000 --> 00:08:13,000
587
+ Let's stop.
588
+
589
+ 148
590
+ 00:08:13,000 --> 00:08:13,000
591
+ Here we go.
592
+
593
+ 149
594
+ 00:08:13,000 --> 00:08:20,000
595
+ So I'm going to go to Google, and here we go with all kinds of certificates.
596
+
597
+ 150
598
+ 00:08:20,000 --> 00:08:22,000
599
+ All these names here are going to start popping up.
600
+
601
+ 151
602
+ 00:08:23,000 --> 00:08:30,000
603
+ Uh, and notice I have uh, Comodo certificates are popular, GoDaddy certificates are popular.
604
+
605
+ 152
606
+ 00:08:30,000 --> 00:08:32,000
607
+ There's one that says cheap SSL.
608
+
609
+ 153
610
+ 00:08:32,000 --> 00:08:34,000
611
+ I use this one on a private web server.
612
+
613
+ 154
614
+ 00:08:36,000 --> 00:08:38,000
615
+ Uh, you can get them from Digicert.
616
+
617
+ 155
618
+ 00:08:38,000 --> 00:08:43,000
619
+ GoDaddy and Digicert is going to be your big player in the game.
620
+
621
+ 156
622
+ 00:08:43,000 --> 00:08:48,000
623
+ So if you want a certificate, this is going to be where you're going to get the the biggest, uh,
624
+
625
+ 157
626
+ 00:08:48,000 --> 00:08:56,000
627
+ certificates from like the highest name I would say comes from Digicert, but Digicert certificates
628
+
629
+ 158
630
+ 00:08:56,000 --> 00:08:57,000
631
+ are not cheap.
632
+
633
+ 159
634
+ 00:08:58,000 --> 00:09:03,000
635
+ They're pretty expensive and they do have extended validation certificates and so on.
636
+
637
+ 160
638
+ 00:09:03,000 --> 00:09:03,000
639
+ Okay.
640
+
641
+ 161
642
+ 00:09:03,000 --> 00:09:05,000
643
+ So you guys can check that if you want a certificate.
644
+
645
+ 162
646
+ 00:09:05,000 --> 00:09:10,000
647
+ There's tons of certificate external parties that you can get a third party cert from.
648
+
649
+ 163
650
+ 00:09:10,000 --> 00:09:13,000
651
+ But the question is why would you want a third party cert.
652
+
653
+ 164
654
+ 00:09:13,000 --> 00:09:16,000
655
+ And the reason is a third party certificate.
656
+
657
+ 165
658
+ 00:09:16,000 --> 00:09:19,000
659
+ It's all about trust.
660
+
661
+ 166
662
+ 00:09:19,000 --> 00:09:27,000
663
+ You see, the difference between a self-signed certificate and a third party certificate is just here.
664
+
665
+ 167
666
+ 00:09:27,000 --> 00:09:30,000
667
+ It's not the level of encryption strength.
668
+
669
+ 168
670
+ 00:09:30,000 --> 00:09:31,000
671
+ It's just a trust.
672
+
673
+ 169
674
+ 00:09:31,000 --> 00:09:40,000
675
+ For example, let's say I create an ID in my house that has my name, my picture, my wait, no, my
676
+
677
+ 170
678
+ 00:09:40,000 --> 00:09:43,000
679
+ height and my eye color and my address.
680
+
681
+ 171
682
+ 00:09:43,000 --> 00:09:49,000
683
+ It has the exact same information as my driver's license.
684
+
685
+ 172
686
+ 00:09:49,000 --> 00:09:55,000
687
+ Then what is the difference between my ID and internal ID and the driver's license?
688
+
689
+ 173
690
+ 00:09:56,000 --> 00:09:59,000
691
+ Nothing except the trust.
692
+
693
+ 174
694
+ 00:09:59,000 --> 00:10:04,000
695
+ People are more likely to trust the DMV stamp than they are to trust me, saying I'm me.
696
+
697
+ 175
698
+ 00:10:04,000 --> 00:10:05,000
699
+ That is the only difference.
700
+
701
+ 176
702
+ 00:10:05,000 --> 00:10:10,000
703
+ So when you get a third party certificate, you're not going to get any more IT security.
704
+
705
+ 177
706
+ 00:10:10,000 --> 00:10:12,000
707
+ I'm going to get a higher level encryption, for example.
708
+
709
+ 178
710
+ 00:10:12,000 --> 00:10:19,000
711
+ In fact, if you generate an internally, you can select to use bigger RSA keys, or you can select
712
+
713
+ 179
714
+ 00:10:19,000 --> 00:10:23,000
715
+ a type of uh, RSA key or the type of hashing you want to use.
716
+
717
+ 180
718
+ 00:10:23,000 --> 00:10:25,000
719
+ So you can actually even make it more secure.
720
+
721
+ 181
722
+ 00:10:25,000 --> 00:10:32,000
723
+ For example, if I internally, if I put the weight on my ID versus the DMV doesn't have that, then
724
+
725
+ 182
726
+ 00:10:32,000 --> 00:10:39,000
727
+ technically my internal ID has more unique identifying factors than the DMV does, but the DMV comes
728
+
729
+ 183
730
+ 00:10:39,000 --> 00:10:40,000
731
+ with that trust factor.
732
+
733
+ 184
734
+ 00:10:41,000 --> 00:10:41,000
735
+ All right.
736
+
737
+ 185
738
+ 00:10:41,000 --> 00:10:42,000
739
+ This trust factor.
740
+
741
+ 186
742
+ 00:10:42,000 --> 00:10:49,000
743
+ So the CA the external CA like Digicert they're going to give you that certificate.
744
+
745
+ 187
746
+ 00:10:49,000 --> 00:10:54,000
747
+ They're going to sign digitally signed with a digital signature on the certificate to verify that it
748
+
749
+ 188
750
+ 00:10:54,000 --> 00:10:55,000
751
+ came from them.
752
+
753
+ 189
754
+ 00:10:56,000 --> 00:10:57,000
755
+ This is going to be.
756
+
757
+ 190
758
+ 00:10:57,000 --> 00:11:00,000
759
+ The trust is most central to most secure communication.
760
+
761
+ 191
762
+ 00:11:00,000 --> 00:11:02,000
763
+ If you're doing Https, where are you going to use this?
764
+
765
+ 192
766
+ 00:11:02,000 --> 00:11:07,000
767
+ You should be using third party certificates for anything that is public facing websites.
768
+
769
+ 193
770
+ 00:11:07,000 --> 00:11:11,000
771
+ Anything that faces the public that public users come to.
772
+
773
+ 194
774
+ 00:11:11,000 --> 00:11:12,000
775
+ The cost?
776
+
777
+ 195
778
+ 00:11:12,000 --> 00:11:14,000
779
+ It will be a cost and it can vary.
780
+
781
+ 196
782
+ 00:11:14,000 --> 00:11:18,000
783
+ You can get a certificate for a few bucks a year to a few thousand dollars a year, depending on the
784
+
785
+ 197
786
+ 00:11:18,000 --> 00:11:19,000
787
+ entity.
788
+
789
+ 198
790
+ 00:11:19,000 --> 00:11:24,000
791
+ I'm not going to get into the exact why it depends on warranty and how much you trust them, and if
792
+
793
+ 199
794
+ 00:11:24,000 --> 00:11:27,000
795
+ they can get hacked and how secure they are.
796
+
797
+ 200
798
+ 00:11:28,000 --> 00:11:29,000
799
+ I'm not going to get into all that.
800
+
801
+ 201
802
+ 00:11:29,000 --> 00:11:30,000
803
+ It's not needed for your course, but it does.
804
+
805
+ 202
806
+ 00:11:30,000 --> 00:11:32,000
807
+ There is a cost associated with this.
808
+
809
+ 203
810
+ 00:11:33,000 --> 00:11:35,000
811
+ Bottom line goes like this.
812
+
813
+ 204
814
+ 00:11:35,000 --> 00:11:42,000
815
+ If you're going to get a certificate for internal access, and you will never have any kind of external
816
+
817
+ 205
818
+ 00:11:42,000 --> 00:11:49,000
819
+ access into that machine, self-signed certificates may be just fine, but if any external access is
820
+
821
+ 206
822
+ 00:11:49,000 --> 00:11:56,000
823
+ required to that machine, for example, like a public website, make sure to get a third party certificate.
824
+
07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt ADDED
@@ -0,0 +1,220 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:00,000
3
+ Okay.
4
+
5
+ 2
6
+ 00:00:00,000 --> 00:00:06,000
7
+ When you're building a PKI, especially internally, you're going to want to understand how the structure
8
+
9
+ 3
10
+ 00:00:06,000 --> 00:00:08,000
11
+ of the PKI is laid out.
12
+
13
+ 4
14
+ 00:00:08,000 --> 00:00:14,000
15
+ So in this video, we want to take a look at that particular structure, uh, of a PKI.
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:18,000
19
+ Now, this this topic in particular is called the root of trust.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:20,000
23
+ And it's how the PKI are managed.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:21,000
27
+ It's basically how you structure it.
28
+
29
+ 8
30
+ 00:00:22,000 --> 00:00:27,000
31
+ So when you set up a PKI, you have a root CA.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:30,000
35
+ Underneath that you have what's called subordinate CAS.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:30,000
39
+ All right.
40
+
41
+ 11
42
+ 00:00:30,000 --> 00:00:32,000
43
+ Now why do we have this?
44
+
45
+ 12
46
+ 00:00:32,000 --> 00:00:34,000
47
+ Well you see this root CA.
48
+
49
+ 13
50
+ 00:00:34,000 --> 00:00:37,000
51
+ This root CA technically doesn't issue certificates.
52
+
53
+ 14
54
+ 00:00:37,000 --> 00:00:39,000
55
+ Let's go back to the process of getting a certificate.
56
+
57
+ 15
58
+ 00:00:39,000 --> 00:00:44,000
59
+ If you remember in that process the CA digitally signs your certificate.
60
+
61
+ 16
62
+ 00:00:45,000 --> 00:00:52,000
63
+ If you remember how a digital signature works is that the CA utilizes its private key, it hashes all
64
+
65
+ 17
66
+ 00:00:52,000 --> 00:00:53,000
67
+ the information on your.
68
+
69
+ 18
70
+ 00:00:53,000 --> 00:00:58,000
71
+ The way it's done is that it will hash all the information on a certificate to company.
72
+
73
+ 19
74
+ 00:00:58,000 --> 00:01:04,000
75
+ Name your domain name, uh, the certificate start and end dates.
76
+
77
+ 20
78
+ 00:01:04,000 --> 00:01:10,000
79
+ It then hashes all this information and then it encrypts it with its private key.
80
+
81
+ 21
82
+ 00:01:10,000 --> 00:01:11,000
83
+ Remember how signatures are done.
84
+
85
+ 22
86
+ 00:01:12,000 --> 00:01:18,000
87
+ So if that certificate like for example, let's say Digicert.
88
+
89
+ 23
90
+ 00:01:18,000 --> 00:01:19,000
91
+ If Digicert.
92
+
93
+ 24
94
+ 00:01:20,000 --> 00:01:26,000
95
+ Ever gets compromised and their private key is compromised.
96
+
97
+ 25
98
+ 00:01:26,000 --> 00:01:33,000
99
+ Every single certificate, the millions and millions of certificate that Digicert has ever given out,
100
+
101
+ 26
102
+ 00:01:33,000 --> 00:01:35,000
103
+ becomes invalid instantly.
104
+
105
+ 27
106
+ 00:01:35,000 --> 00:01:38,000
107
+ Because then anybody could remake the certificate because they have the private key.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:40,000
111
+ And of course, everybody had the public key.
112
+
113
+ 29
114
+ 00:01:40,000 --> 00:01:41,000
115
+ It was always public.
116
+
117
+ 30
118
+ 00:01:41,000 --> 00:01:51,000
119
+ So in order to help minimize this kind of impact, what we do is we set up a root CA and then subordinate
120
+
121
+ 31
122
+ 00:01:51,000 --> 00:01:51,000
123
+ CAS.
124
+
125
+ 32
126
+ 00:01:51,000 --> 00:01:55,000
127
+ Now the reason why you have this is because of this.
128
+
129
+ 33
130
+ 00:01:55,000 --> 00:01:57,000
131
+ You you set up a root CA.
132
+
133
+ 34
134
+ 00:01:58,000 --> 00:02:05,000
135
+ And this root CA will then issue a certificate to the subordinate CAS which can then issue it to even
136
+
137
+ 35
138
+ 00:02:05,000 --> 00:02:06,000
139
+ lower CAS.
140
+
141
+ 36
142
+ 00:02:06,000 --> 00:02:11,000
143
+ The reason you do this is because then you can take the root CA offline when I mean offline.
144
+
145
+ 37
146
+ 00:02:11,000 --> 00:02:17,000
147
+ This is a computer that is literally unplugged, shut off, and put into a vault a couple thousand feet
148
+
149
+ 38
150
+ 00:02:17,000 --> 00:02:23,000
151
+ in the air because this is certify and this and this is certifying this.
152
+
153
+ 39
154
+ 00:02:23,000 --> 00:02:31,000
155
+ So technically speaking, if somebody hacks the company and they hack this lower CA right here at the
156
+
157
+ 40
158
+ 00:02:31,000 --> 00:02:34,000
159
+ bottom, then you know what?
160
+
161
+ 41
162
+ 00:02:34,000 --> 00:02:39,000
163
+ All the certificate that's issued by this cert by DCA is invalidated.
164
+
165
+ 42
166
+ 00:02:39,000 --> 00:02:42,000
167
+ Not everything in the entire organization.
168
+
169
+ 43
170
+ 00:02:42,000 --> 00:02:48,000
171
+ So what this does is this helps to minimize the impact of the data breach or the attack.
172
+
173
+ 44
174
+ 00:02:48,000 --> 00:02:49,000
175
+ That's what you would want.
176
+
177
+ 45
178
+ 00:02:49,000 --> 00:02:55,000
179
+ This you don't you never want to just start issuing certificate from your root CA because if that root
180
+
181
+ 46
182
+ 00:02:55,000 --> 00:02:56,000
183
+ CA.
184
+
185
+ 47
186
+ 00:02:57,000 --> 00:02:58,000
187
+ Is.
188
+
189
+ 48
190
+ 00:02:59,000 --> 00:03:03,000
191
+ If that route C is ever compromised, every search you've ever given is invalidated.
192
+
193
+ 49
194
+ 00:03:03,000 --> 00:03:06,000
195
+ But if you branch it off into four subordinates.
196
+
197
+ 50
198
+ 00:03:07,000 --> 00:03:11,000
199
+ Then if one of those is compromised, there's just those certs are compromised, not the other three.
200
+
201
+ 51
202
+ 00:03:11,000 --> 00:03:16,000
203
+ So that's why you would want to use this kind of structure.
204
+
205
+ 52
206
+ 00:03:16,000 --> 00:03:19,000
207
+ Now this kind of structure is only done well.
208
+
209
+ 53
210
+ 00:03:19,000 --> 00:03:20,000
211
+ It's done basically for two reasons.
212
+
213
+ 54
214
+ 00:03:20,000 --> 00:03:25,000
215
+ Number one easier to administer and of course for the data protection.
216
+
217
+ 55
218
+ 00:03:25,000 --> 00:03:29,000
219
+ That way if something happens, not everything becomes invalidated.
220
+
07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt ADDED
@@ -0,0 +1,372 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:00,000
3
+ Okay.
4
+
5
+ 2
6
+ 00:00:00,000 --> 00:00:05,000
7
+ When you receive a certificate from someone, you have to verify that it actually came from them.
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:11,000
11
+ There's a couple of things here that we need to know for our exam when it comes to this process of verification.
12
+
13
+ 4
14
+ 00:00:11,000 --> 00:00:14,000
15
+ And again, this is when a user wants to validate your certificate.
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:19,000
19
+ So somebody comes to an app, maybe like a web app that you made or a device that you're using.
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:23,000
23
+ Maybe you have certificates installed on your on your firewall for VPN and so on.
24
+
25
+ 7
26
+ 00:00:23,000 --> 00:00:25,000
27
+ Somebody comes there and they get a certificate.
28
+
29
+ 8
30
+ 00:00:25,000 --> 00:00:27,000
31
+ They want to verify that it's coming from you.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:31,000
35
+ If I get into that, do I want to talk about a firm that you may see appear on your exam?
36
+
37
+ 10
38
+ 00:00:31,000 --> 00:00:32,000
39
+ It's called certificate pinning.
40
+
41
+ 11
42
+ 00:00:32,000 --> 00:00:35,000
43
+ This is a techniques that helps to prevent man in the middle attacks.
44
+
45
+ 12
46
+ 00:00:35,000 --> 00:00:39,000
47
+ What it does is that it hard codes the SSL public key into an app.
48
+
49
+ 13
50
+ 00:00:40,000 --> 00:00:44,000
51
+ This means that when the output device communicates with the server to compare the SSL certificates
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:46,000
55
+ public key with the one in the app.
56
+
57
+ 15
58
+ 00:00:46,000 --> 00:00:48,000
59
+ Now let me give you an example how this works.
60
+
61
+ 16
62
+ 00:00:48,000 --> 00:00:48,000
63
+ So.
64
+
65
+ 17
66
+ 00:00:49,000 --> 00:00:54,000
67
+ Let's say you have an application, and every time people come, they get your certificate and then
68
+
69
+ 18
70
+ 00:00:54,000 --> 00:00:55,000
71
+ they check the certificate.
72
+
73
+ 19
74
+ 00:00:55,000 --> 00:01:00,000
75
+ Now, what you can do in order to prevent people from intercepting or changing anything, you can hardcode
76
+
77
+ 20
78
+ 00:01:00,000 --> 00:01:02,000
79
+ the public key in the application itself.
80
+
81
+ 21
82
+ 00:01:02,000 --> 00:01:07,000
83
+ So then the certificate that's given to them by the SSL process, they can then compare it to the application's
84
+
85
+ 22
86
+ 00:01:07,000 --> 00:01:08,000
87
+ public key.
88
+
89
+ 23
90
+ 00:01:08,000 --> 00:01:16,000
91
+ That way no one can intercept the certificate or change it and say that this is their certificate of
92
+
93
+ 24
94
+ 00:01:16,000 --> 00:01:19,000
95
+ any kind, because you have a hardcoded the public key in the app.
96
+
97
+ 25
98
+ 00:01:20,000 --> 00:01:21,000
99
+ Okay.
100
+
101
+ 26
102
+ 00:01:21,000 --> 00:01:24,000
103
+ Let's move on here quickly to the verification process.
104
+
105
+ 27
106
+ 00:01:24,000 --> 00:01:28,000
107
+ So when you get a certificate all right a couple of things here.
108
+
109
+ 28
110
+ 00:01:28,000 --> 00:01:33,000
111
+ The certificate verification process includes verifying the digital signature of the CA is authentic.
112
+
113
+ 29
114
+ 00:01:33,000 --> 00:01:35,000
115
+ And they trust the CA.
116
+
117
+ 30
118
+ 00:01:35,000 --> 00:01:39,000
119
+ So when you receive a certificate you're going to check okay.
120
+
121
+ 31
122
+ 00:01:39,000 --> 00:01:41,000
123
+ Who the certificate came from.
124
+
125
+ 32
126
+ 00:01:41,000 --> 00:01:42,000
127
+ Digicert.
128
+
129
+ 33
130
+ 00:01:42,000 --> 00:01:49,000
131
+ I want you guys to keep in mind that your computer has a list of already pre-approved certificate authorities
132
+
133
+ 34
134
+ 00:01:49,000 --> 00:01:50,000
135
+ that it trusts.
136
+
137
+ 35
138
+ 00:01:50,000 --> 00:01:55,000
139
+ You're then going to check that a signature on it to make sure it's good.
140
+
141
+ 36
142
+ 00:01:56,000 --> 00:02:02,000
143
+ One of the things that you guys will check is what's called a CRL, the certificate revocation list.
144
+
145
+ 37
146
+ 00:02:02,000 --> 00:02:06,000
147
+ This is a published list of certificates that have been revoked.
148
+
149
+ 38
150
+ 00:02:06,000 --> 00:02:08,000
151
+ Let's talk about this revocation process.
152
+
153
+ 39
154
+ 00:02:08,000 --> 00:02:16,000
155
+ Sometimes when you get a certificate, you yourself may want to revoke the certificate for reasons such
156
+
157
+ 40
158
+ 00:02:16,000 --> 00:02:19,000
159
+ as you're changing the server and the server is not valid anymore.
160
+
161
+ 41
162
+ 00:02:19,000 --> 00:02:23,000
163
+ The server crashed, your server was hacked, and you lost the private key.
164
+
165
+ 42
166
+ 00:02:23,000 --> 00:02:27,000
167
+ Something happened internally and you don't want to use that certificate anymore.
168
+
169
+ 43
170
+ 00:02:27,000 --> 00:02:33,000
171
+ So you call your certificate provider like Digicert and say, well, can you reissue this cert?
172
+
173
+ 44
174
+ 00:02:33,000 --> 00:02:34,000
175
+ Desert we have is no good.
176
+
177
+ 45
178
+ 00:02:35,000 --> 00:02:37,000
179
+ So maybe your server got hacked.
180
+
181
+ 46
182
+ 00:02:37,000 --> 00:02:40,000
183
+ So you call Digicert and say, well, my server got hacked.
184
+
185
+ 47
186
+ 00:02:40,000 --> 00:02:42,000
187
+ I need a brand new certificate.
188
+
189
+ 48
190
+ 00:02:42,000 --> 00:02:43,000
191
+ So Digicert says, no problem.
192
+
193
+ 49
194
+ 00:02:43,000 --> 00:02:48,000
195
+ Here's a brand new certificate with a and you generate a new public private key pair.
196
+
197
+ 50
198
+ 00:02:48,000 --> 00:02:50,000
199
+ Now what happens to that old certificate?
200
+
201
+ 51
202
+ 00:02:50,000 --> 00:02:53,000
203
+ You see the old certificate that Digicert issued?
204
+
205
+ 52
206
+ 00:02:53,000 --> 00:02:56,000
207
+ It's still technically valid.
208
+
209
+ 53
210
+ 00:02:56,000 --> 00:02:56,000
211
+ Here's why.
212
+
213
+ 54
214
+ 00:02:56,000 --> 00:03:00,000
215
+ Because the public the the expiration date hasn't occurred yet.
216
+
217
+ 55
218
+ 00:03:00,000 --> 00:03:01,000
219
+ So it's not expired.
220
+
221
+ 56
222
+ 00:03:02,000 --> 00:03:04,000
223
+ The signature is still valid.
224
+
225
+ 57
226
+ 00:03:04,000 --> 00:03:10,000
227
+ Remember, signature is the hash of the certificate encrypted with the CA's private key.
228
+
229
+ 58
230
+ 00:03:11,000 --> 00:03:13,000
231
+ That's still valid.
232
+
233
+ 59
234
+ 00:03:13,000 --> 00:03:16,000
235
+ So anybody that receives that certificate is going to think it's valid.
236
+
237
+ 60
238
+ 00:03:16,000 --> 00:03:24,000
239
+ So what we do is we will publish a list of certificates that's revoked.
240
+
241
+ 61
242
+ 00:03:24,000 --> 00:03:27,000
243
+ So when people come to the website, they're going to check the CRL list.
244
+
245
+ 62
246
+ 00:03:27,000 --> 00:03:32,000
247
+ Or they check this thing called Ocsp, an online certificate status protocol.
248
+
249
+ 63
250
+ 00:03:32,000 --> 00:03:35,000
251
+ This is a real time validation with the CA.
252
+
253
+ 64
254
+ 00:03:35,000 --> 00:03:36,000
255
+ This is a is this valid?
256
+
257
+ 65
258
+ 00:03:36,000 --> 00:03:37,000
259
+ The CA is like yeah that's good.
260
+
261
+ 66
262
+ 00:03:38,000 --> 00:03:43,000
263
+ Now the certificate usually contains the data that you're going to be trusting such as that public key.
264
+
265
+ 67
266
+ 00:03:43,000 --> 00:03:46,000
267
+ So this is the revocation that I was mentioning.
268
+
269
+ 68
270
+ 00:03:46,000 --> 00:03:51,000
271
+ So when it's compromised it gets added to the certificate revocation list.
272
+
273
+ 69
274
+ 00:03:51,000 --> 00:03:57,000
275
+ If you want a real time validation that the certificate is actually good.
276
+
277
+ 70
278
+ 00:03:57,000 --> 00:04:00,000
279
+ Then you use all CSP.
280
+
281
+ 71
282
+ 00:04:00,000 --> 00:04:01,000
283
+ Know that for your exam.
284
+
285
+ 72
286
+ 00:04:01,000 --> 00:04:02,000
287
+ There's a real time.
288
+
289
+ 73
290
+ 00:04:02,000 --> 00:04:07,000
291
+ So right now, almost all of us, every time we go to Amazon or we get the certificate, we use this
292
+
293
+ 74
294
+ 00:04:07,000 --> 00:04:10,000
295
+ protocol to check if that certificate is still valid.
296
+
297
+ 75
298
+ 00:04:11,000 --> 00:04:15,000
299
+ Another time you may see on your exam is something we call certificate stapling.
300
+
301
+ 76
302
+ 00:04:15,000 --> 00:04:16,000
303
+ All right.
304
+
305
+ 77
306
+ 00:04:16,000 --> 00:04:20,000
307
+ And what this does is that it avoids the client from sending the Ocsp request.
308
+
309
+ 78
310
+ 00:04:20,000 --> 00:04:27,000
311
+ Instead, the web server itself checks the validation with the CA now certificate stapling is this.
312
+
313
+ 79
314
+ 00:04:27,000 --> 00:04:34,000
315
+ Every time you get, uh, the certificate, you have to check with the ocsp.
316
+
317
+ 80
318
+ 00:04:34,000 --> 00:04:35,000
319
+ Is it good?
320
+
321
+ 81
322
+ 00:04:35,000 --> 00:04:35,000
323
+ Okay, great.
324
+
325
+ 82
326
+ 00:04:35,000 --> 00:04:36,000
327
+ Let me use it.
328
+
329
+ 83
330
+ 00:04:36,000 --> 00:04:44,000
331
+ How about if I just the actual web server gets the validation, and then when you receive the certificate,
332
+
333
+ 84
334
+ 00:04:44,000 --> 00:04:48,000
335
+ you're receiving the validation that you're looking for and the certificate.
336
+
337
+ 85
338
+ 00:04:48,000 --> 00:04:48,000
339
+ So that's what this does.
340
+
341
+ 86
342
+ 00:04:48,000 --> 00:04:51,000
343
+ It makes it a lot easier so you don't have to waste time.
344
+
345
+ 87
346
+ 00:04:51,000 --> 00:04:52,000
347
+ Keep going here.
348
+
349
+ 88
350
+ 00:04:53,000 --> 00:04:54,000
351
+ Okay.
352
+
353
+ 89
354
+ 00:04:54,000 --> 00:04:56,000
355
+ Revocation is a is a pretty important thing.
356
+
357
+ 90
358
+ 00:04:56,000 --> 00:05:01,000
359
+ At some point, if in your history of managing web servers or managing this kind of technology like
360
+
361
+ 91
362
+ 00:05:01,000 --> 00:05:06,000
363
+ SSL, you're probably going to have to revoke a cert when a cert is revoked.
364
+
365
+ 92
366
+ 00:05:06,000 --> 00:05:11,000
367
+ It has to be a way for other users in the public internet, or in turn, your organization to note that
368
+
369
+ 93
370
+ 00:05:11,000 --> 00:05:15,000
371
+ certificate is no good and these are the ways that it's done.
372
+
07 - Cryptography/021 Steganography OB 1.4_en.srt ADDED
@@ -0,0 +1,392 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ Okay, let's talk of a pretty cool technology called steganography.
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:11,000
7
+ Now, steganography is basically a technique where you're able to encode a hidden message into different
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:17,000
11
+ things, such as pictures, audio files, video files, or text files.
12
+
13
+ 4
14
+ 00:00:17,000 --> 00:00:20,000
15
+ And I have a link here that I want you guys to try.
16
+
17
+ 5
18
+ 00:00:20,000 --> 00:00:25,000
19
+ I'm going to show you guys how to use that, and I'm going to show you guys how we can take an image
20
+
21
+ 6
22
+ 00:00:25,000 --> 00:00:27,000
23
+ and encode a secret message into it.
24
+
25
+ 7
26
+ 00:00:27,000 --> 00:00:31,000
27
+ Why is this bad and somewhat good?
28
+
29
+ 8
30
+ 00:00:31,000 --> 00:00:38,000
31
+ So let's say you're working in an organization and you are a bad person, and you want to get secret
32
+
33
+ 9
34
+ 00:00:38,000 --> 00:00:44,000
35
+ data out of that organization right in front of their faces, and they would never know.
36
+
37
+ 10
38
+ 00:00:44,000 --> 00:00:46,000
39
+ So here's what you do.
40
+
41
+ 11
42
+ 00:00:46,000 --> 00:00:51,000
43
+ You go to the office and you take a group picture with all your bosses and everyone, and then you take
44
+
45
+ 12
46
+ 00:00:51,000 --> 00:00:53,000
47
+ that picture and you put it on your computer.
48
+
49
+ 13
50
+ 00:00:53,000 --> 00:01:00,000
51
+ What you do then is you take the company's secret information, secret data, and you encode it into
52
+
53
+ 14
54
+ 00:01:00,000 --> 00:01:00,000
55
+ the picture.
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:07,000
59
+ Then what you do is you email the picture out outside to your personal private email.
60
+
61
+ 16
62
+ 00:01:07,000 --> 00:01:12,000
63
+ And then what happens is when you get home, you decode the picture and you take the message out the
64
+
65
+ 17
66
+ 00:01:12,000 --> 00:01:13,000
67
+ picture.
68
+
69
+ 18
70
+ 00:01:13,000 --> 00:01:19,000
71
+ So this picture is flying around the internet, but the picture is actually just a front for the secret
72
+
73
+ 19
74
+ 00:01:19,000 --> 00:01:21,000
75
+ message that lies behind it.
76
+
77
+ 20
78
+ 00:01:21,000 --> 00:01:24,000
79
+ It's actually really easy to do, and you can even do a website that does it.
80
+
81
+ 21
82
+ 00:01:24,000 --> 00:01:26,000
83
+ And I'll show you guys how easy it is.
84
+
85
+ 22
86
+ 00:01:26,000 --> 00:01:31,000
87
+ Now, what I'm describing to you here is called image steganography.
88
+
89
+ 23
90
+ 00:01:31,000 --> 00:01:37,000
91
+ And this what they do is they modify LSB the least significant bit in the image.
92
+
93
+ 24
94
+ 00:01:37,000 --> 00:01:42,000
95
+ Basically, they're going to modify the image to the point where the human eyes can notice that the
96
+
97
+ 25
98
+ 00:01:42,000 --> 00:01:44,000
99
+ image has actually been modified.
100
+
101
+ 26
102
+ 00:01:44,000 --> 00:01:50,000
103
+ You could also do this with audio file concealing the information within audio files, or particularly
104
+
105
+ 27
106
+ 00:01:50,000 --> 00:01:54,000
107
+ all kinds of video files like MP4 video files are famous for this.
108
+
109
+ 28
110
+ 00:01:54,000 --> 00:01:59,000
111
+ You can even embed it into white spaces into certain text document.
112
+
113
+ 29
114
+ 00:01:59,000 --> 00:02:06,000
115
+ Now for this I want to show you guys how it's done, and I'll give you guys some ways of how to detect
116
+
117
+ 30
118
+ 00:02:06,000 --> 00:02:06,000
119
+ it.
120
+
121
+ 31
122
+ 00:02:06,000 --> 00:02:07,000
123
+ So let's take a look here.
124
+
125
+ 32
126
+ 00:02:07,000 --> 00:02:11,000
127
+ Here I am at that particular website that I just showed you.
128
+
129
+ 33
130
+ 00:02:11,000 --> 00:02:14,000
131
+ Now on my desktop.
132
+
133
+ 34
134
+ 00:02:14,000 --> 00:02:15,000
135
+ Let me pull up my desktop here.
136
+
137
+ 35
138
+ 00:02:17,000 --> 00:02:19,000
139
+ On my desktop, I have an image.
140
+
141
+ 36
142
+ 00:02:21,000 --> 00:02:24,000
143
+ I have this image that I just downloaded, royalty free image.
144
+
145
+ 37
146
+ 00:02:24,000 --> 00:02:26,000
147
+ And let's see what it looks like.
148
+
149
+ 38
150
+ 00:02:26,000 --> 00:02:28,000
151
+ This image of a laptop that I have.
152
+
153
+ 39
154
+ 00:02:28,000 --> 00:02:33,000
155
+ So what I'm going to do is I'm going to encode select file.
156
+
157
+ 40
158
+ 00:02:33,000 --> 00:02:34,000
159
+ I'm going to choose my image.
160
+
161
+ 41
162
+ 00:02:36,000 --> 00:02:37,000
163
+ There is my desktop.
164
+
165
+ 42
166
+ 00:02:37,000 --> 00:02:38,000
167
+ Here we go.
168
+
169
+ 43
170
+ 00:02:38,000 --> 00:02:39,000
171
+ Image image image.
172
+
173
+ 44
174
+ 00:02:39,000 --> 00:02:47,000
175
+ So I select the image and I'm going to put a message that says Andrew has many certifications.
176
+
177
+ 45
178
+ 00:02:47,000 --> 00:02:48,000
179
+ That's my message.
180
+
181
+ 46
182
+ 00:02:48,000 --> 00:02:50,000
183
+ And this is your original image.
184
+
185
+ 47
186
+ 00:02:50,000 --> 00:02:53,000
187
+ Now you're not going to notice a difference when it encodes it.
188
+
189
+ 48
190
+ 00:02:54,000 --> 00:02:55,000
191
+ Okay.
192
+
193
+ 49
194
+ 00:02:55,000 --> 00:03:00,000
195
+ So here's the binary representation of the actual image that it's that it's encoding it into.
196
+
197
+ 50
198
+ 00:03:00,000 --> 00:03:05,000
199
+ And here is the actual stick node image.
200
+
201
+ 51
202
+ 00:03:06,000 --> 00:03:07,000
203
+ It says message hidden in the image.
204
+
205
+ 52
206
+ 00:03:07,000 --> 00:03:10,000
207
+ You can't tell the difference between that and this.
208
+
209
+ 53
210
+ 00:03:11,000 --> 00:03:16,000
211
+ Now, when you try it on your computer, try to see the human eyes cannot tell.
212
+
213
+ 54
214
+ 00:03:16,000 --> 00:03:19,000
215
+ Now what I'm going to do is I'm going to right click and I'm going to save this one.
216
+
217
+ 55
218
+ 00:03:21,000 --> 00:03:24,000
219
+ And uh, we're going to call it now, I already tried this.
220
+
221
+ 56
222
+ 00:03:24,000 --> 00:03:27,000
223
+ I wanted to try it before it before showing to you.
224
+
225
+ 57
226
+ 00:03:27,000 --> 00:03:34,000
227
+ So we're going to call S I stick node image for now dot png.
228
+
229
+ 58
230
+ 00:03:34,000 --> 00:03:34,000
231
+ All right.
232
+
233
+ 59
234
+ 00:03:34,000 --> 00:03:36,000
235
+ So we're going to save this.
236
+
237
+ 60
238
+ 00:03:37,000 --> 00:03:38,000
239
+ All right, that's it.
240
+
241
+ 61
242
+ 00:03:38,000 --> 00:03:39,000
243
+ It's saved.
244
+
245
+ 62
246
+ 00:03:39,000 --> 00:03:43,000
247
+ Now, if I open up the image, you notice it pretty much is the same thing.
248
+
249
+ 63
250
+ 00:03:43,000 --> 00:03:49,000
251
+ Now, let's say I can give this image to a lot of people around the internet.
252
+
253
+ 64
254
+ 00:03:49,000 --> 00:03:53,000
255
+ Uh, no one would know unless you actually know there is an image.
256
+
257
+ 65
258
+ 00:03:53,000 --> 00:03:55,000
259
+ So let's close out this site.
260
+
261
+ 66
262
+ 00:03:55,000 --> 00:03:57,000
263
+ I'm going to reopen it.
264
+
265
+ 67
266
+ 00:03:59,000 --> 00:04:00,000
267
+ So you can see it's all brand new.
268
+
269
+ 68
270
+ 00:04:00,000 --> 00:04:02,000
271
+ So I'm going to go to decode this time.
272
+
273
+ 69
274
+ 00:04:02,000 --> 00:04:04,000
275
+ I'm going to select the file.
276
+
277
+ 70
278
+ 00:04:05,000 --> 00:04:07,000
279
+ Including the downloads folder.
280
+
281
+ 71
282
+ 00:04:07,000 --> 00:04:07,000
283
+ We had it.
284
+
285
+ 72
286
+ 00:04:08,000 --> 00:04:09,000
287
+ Here we go.
288
+
289
+ 73
290
+ 00:04:10,000 --> 00:04:12,000
291
+ So this is the image the input I'm just going to click on decode.
292
+
293
+ 74
294
+ 00:04:13,000 --> 00:04:15,000
295
+ And notice my message has just popped up.
296
+
297
+ 75
298
+ 00:04:16,000 --> 00:04:18,000
299
+ You can see the message right there at the top.
300
+
301
+ 76
302
+ 00:04:19,000 --> 00:04:19,000
303
+ All right.
304
+
305
+ 77
306
+ 00:04:19,000 --> 00:04:20,000
307
+ Very good.
308
+
309
+ 78
310
+ 00:04:20,000 --> 00:04:22,000
311
+ So that is steganography.
312
+
313
+ 79
314
+ 00:04:22,000 --> 00:04:29,000
315
+ Steganography is just the way of embedding a message into an image, or a text file, or a movie file
316
+
317
+ 80
318
+ 00:04:29,000 --> 00:04:29,000
319
+ or audio file.
320
+
321
+ 81
322
+ 00:04:29,000 --> 00:04:35,000
323
+ Now, the way you can tell is the file size.
324
+
325
+ 82
326
+ 00:04:35,000 --> 00:04:35,000
327
+ All right.
328
+
329
+ 83
330
+ 00:04:35,000 --> 00:04:40,000
331
+ The way you can tell if an image has signal, you would need to have that original file.
332
+
333
+ 84
334
+ 00:04:40,000 --> 00:04:46,000
335
+ And if you believe that an image has some kind of steganography behind it, look at the file size.
336
+
337
+ 85
338
+ 00:04:46,000 --> 00:04:49,000
339
+ Another thing you can do is run it against a hash checker.
340
+
341
+ 86
342
+ 00:04:49,000 --> 00:04:53,000
343
+ The hash of the images would be different because one of them just has more information than the other.
344
+
345
+ 87
346
+ 00:04:53,000 --> 00:04:55,000
347
+ There are some ways of checking.
348
+
349
+ 88
350
+ 00:04:55,000 --> 00:04:58,000
351
+ Other than that, there's not many different ways of stopping this thing.
352
+
353
+ 89
354
+ 00:04:58,000 --> 00:05:04,000
355
+ Steganography is difficult to detect, but it's as difficult to detect.
356
+
357
+ 90
358
+ 00:05:05,000 --> 00:05:14,000
359
+ But this is why you should limit the output in or send in of things like, uh, images and audio files
360
+
361
+ 91
362
+ 00:05:14,000 --> 00:05:15,000
363
+ outside your organization.
364
+
365
+ 92
366
+ 00:05:15,000 --> 00:05:20,000
367
+ Because now that you know that this exists, maybe you shouldn't allow images to go out.
368
+
369
+ 93
370
+ 00:05:20,000 --> 00:05:25,000
371
+ In fact, one of the dumbest things I see organizations do sometimes.
372
+
373
+ 94
374
+ 00:05:25,000 --> 00:05:32,000
375
+ I got an email from a bank, like legitimate email from a representative of a bank, and in it they
376
+
377
+ 95
378
+ 00:05:32,000 --> 00:05:35,000
379
+ have the logo of the bank and the email signature of the person.
380
+
381
+ 96
382
+ 00:05:35,000 --> 00:05:42,000
383
+ That's smart, because if the head of the bank realizes that they can embed messages into that little
384
+
385
+ 97
386
+ 00:05:42,000 --> 00:05:44,000
387
+ logo, I don't think they would have allowed it.
388
+
389
+ 98
390
+ 00:05:44,000 --> 00:05:49,000
391
+ So it's important to know what this thing is and realize it's difficult to detect.
392
+
07 - Cryptography/022 Blockchain OB 1.4_en.srt ADDED
@@ -0,0 +1,476 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:03,000
3
+ In this video, we're going to talk of a pretty famous technology.
4
+
5
+ 2
6
+ 00:00:03,000 --> 00:00:06,000
7
+ And that technology is called blockchain.
8
+
9
+ 3
10
+ 00:00:06,000 --> 00:00:09,000
11
+ Now blockchain I'm going to show you guys how a blockchain is built.
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:15,000
15
+ But this particular technology is famous in cryptocurrencies where most people hears it from.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:21,000
19
+ But blockchain can be applied to many different applications, whether it's an accounting application,
20
+
21
+ 6
22
+ 00:00:21,000 --> 00:00:24,000
23
+ banking transactions or all different kinds of financial transactions.
24
+
25
+ 7
26
+ 00:00:24,000 --> 00:00:25,000
27
+ You can use a blockchain.
28
+
29
+ 8
30
+ 00:00:25,000 --> 00:00:27,000
31
+ So it's not just for cryptocurrency.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:30,000
35
+ In fact, this video has nothing to do with cryptocurrency.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:31,000
39
+ Let's get started.
40
+
41
+ 11
42
+ 00:00:31,000 --> 00:00:38,000
43
+ So blockchain let's take a look at some definitions before I show you exactly how a blockchain is built.
44
+
45
+ 12
46
+ 00:00:38,000 --> 00:00:46,000
47
+ So a blockchain is known as a decentralized and distributed ledger technology known for its role in
48
+
49
+ 13
50
+ 00:00:46,000 --> 00:00:47,000
51
+ underpinning cryptocurrency.
52
+
53
+ 14
54
+ 00:00:47,000 --> 00:00:53,000
55
+ Like I mentioned now a blockchain is just a chain of blocks where each block represents a list of transaction.
56
+
57
+ 15
58
+ 00:00:53,000 --> 00:00:58,000
59
+ Each transaction in the blockchain is secured through a cryptographic principle known as hashing, which
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:01:00,000
63
+ we covered earlier in the course.
64
+
65
+ 17
66
+ 00:01:00,000 --> 00:01:05,000
67
+ The blockchain is decentralized and maintain across a network of computers across all of the nodes in
68
+
69
+ 18
70
+ 00:01:05,000 --> 00:01:07,000
71
+ that particular system.
72
+
73
+ 19
74
+ 00:01:07,000 --> 00:01:10,000
75
+ It does utilize a hash function.
76
+
77
+ 20
78
+ 00:01:10,000 --> 00:01:15,000
79
+ Each block contains a cryptographic hash of the previous block, chaining them together.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:17,000
83
+ This ensures that each block is added to.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:21,000
87
+ Jim cannot be altered without messing up all the blocks that comes after it.
88
+
89
+ 23
90
+ 00:01:22,000 --> 00:01:24,000
91
+ Lots of information here.
92
+
93
+ 24
94
+ 00:01:24,000 --> 00:01:27,000
95
+ Let me show you it and it'll make more sense.
96
+
97
+ 25
98
+ 00:01:27,000 --> 00:01:29,000
99
+ So I have an image.
100
+
101
+ 26
102
+ 00:01:30,000 --> 00:01:33,000
103
+ Uh, from Money.com.
104
+
105
+ 27
106
+ 00:01:33,000 --> 00:01:38,000
107
+ And I want to show you guys what is, you know, what exactly is how how a blockchain works.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:43,000
111
+ So first of all, when they say the word decentralized ledger, let's take the word ledger.
112
+
113
+ 29
114
+ 00:01:43,000 --> 00:01:48,000
115
+ Ledger literally means list when they say a list of transactions.
116
+
117
+ 30
118
+ 00:01:48,000 --> 00:01:54,000
119
+ When you design a blockchain, you design how many of these transactions are going to be stored on every
120
+
121
+ 31
122
+ 00:01:54,000 --> 00:01:55,000
123
+ single block.
124
+
125
+ 32
126
+ 00:01:55,000 --> 00:01:58,000
127
+ So every block can hold a list of transactions.
128
+
129
+ 33
130
+ 00:01:58,000 --> 00:02:02,000
131
+ Let's say you're a reseller and you're selling books.
132
+
133
+ 34
134
+ 00:02:03,000 --> 00:02:04,000
135
+ Okay.
136
+
137
+ 35
138
+ 00:02:04,000 --> 00:02:07,000
139
+ Each block for you holds three transactions.
140
+
141
+ 36
142
+ 00:02:07,000 --> 00:02:12,000
143
+ It holds who bought the book when they bought the book, and how much money they spent buying the book.
144
+
145
+ 37
146
+ 00:02:12,000 --> 00:02:13,000
147
+ And again, this is a list.
148
+
149
+ 38
150
+ 00:02:13,000 --> 00:02:18,000
151
+ Anything that you can, anything that you can put a make a list out of, you can make a blockchain out
152
+
153
+ 39
154
+ 00:02:18,000 --> 00:02:18,000
155
+ of.
156
+
157
+ 40
158
+ 00:02:18,000 --> 00:02:21,000
159
+ So let's say each block holds three transactions.
160
+
161
+ 41
162
+ 00:02:21,000 --> 00:02:26,000
163
+ And I'll show you why the blockchain is so powerful and why people like using it.
164
+
165
+ 42
166
+ 00:02:26,000 --> 00:02:28,000
167
+ So each block is three transactions.
168
+
169
+ 43
170
+ 00:02:28,000 --> 00:02:32,000
171
+ So in the first block you put transaction number one.
172
+
173
+ 44
174
+ 00:02:32,000 --> 00:02:38,000
175
+ Let's say Bob bought a book for $10 and the book was, uh, Excel.
176
+
177
+ 45
178
+ 00:02:38,000 --> 00:02:45,000
179
+ Then the second book was bought by Mary for 20 bucks, and she bought a word book.
180
+
181
+ 46
182
+ 00:02:45,000 --> 00:02:49,000
183
+ And, uh, number three was Peter.
184
+
185
+ 47
186
+ 00:02:49,000 --> 00:02:54,000
187
+ He bought a CISSP book for a $30 CISSP book.
188
+
189
+ 48
190
+ 00:02:54,000 --> 00:02:55,000
191
+ It doesn't matter what it is.
192
+
193
+ 49
194
+ 00:02:55,000 --> 00:02:58,000
195
+ Just know it's three transaction.
196
+
197
+ 50
198
+ 00:02:58,000 --> 00:03:06,000
199
+ What you do is you take your entire three transaction, all three of them, everything about them,
200
+
201
+ 51
202
+ 00:03:06,000 --> 00:03:07,000
203
+ and you hash it.
204
+
205
+ 52
206
+ 00:03:07,000 --> 00:03:14,000
207
+ Now, the most famous hash they use is a crypto is a, uh, Sha 256 is the most famous hash they use.
208
+
209
+ 53
210
+ 00:03:14,000 --> 00:03:19,000
211
+ If you remember the hash in videos, how I was able to type text in the box and they generate a hash,
212
+
213
+ 54
214
+ 00:03:19,000 --> 00:03:20,000
215
+ the same thing here.
216
+
217
+ 55
218
+ 00:03:20,000 --> 00:03:23,000
219
+ They're just going to put all the transaction in and boom, generate a hash.
220
+
221
+ 56
222
+ 00:03:23,000 --> 00:03:26,000
223
+ This is the hash that comes out of this block.
224
+
225
+ 57
226
+ 00:03:27,000 --> 00:03:29,000
227
+ There is no previous hash or zero.
228
+
229
+ 58
230
+ 00:03:30,000 --> 00:03:31,000
231
+ Then what they do?
232
+
233
+ 59
234
+ 00:03:32,000 --> 00:03:40,000
235
+ Is they go to the next block and they put another one, two, three transaction.
236
+
237
+ 60
238
+ 00:03:40,000 --> 00:03:41,000
239
+ Whatever they are, it doesn't matter for now.
240
+
241
+ 61
242
+ 00:03:42,000 --> 00:03:45,000
243
+ And then they hash it.
244
+
245
+ 62
246
+ 00:03:45,000 --> 00:03:46,000
247
+ But here's what they do.
248
+
249
+ 63
250
+ 00:03:46,000 --> 00:03:50,000
251
+ This block starts out with the this previous hash.
252
+
253
+ 64
254
+ 00:03:50,000 --> 00:03:55,000
255
+ This hash comes right here 6UP2.
256
+
257
+ 65
258
+ 00:03:55,000 --> 00:04:02,000
259
+ So it takes the three transaction plus this hash to produce this hash.
260
+
261
+ 66
262
+ 00:04:02,000 --> 00:04:11,000
263
+ Then it takes this hash puts it here I'm talking the hash value itself 8Y5C9.
264
+
265
+ 67
266
+ 00:04:11,000 --> 00:04:14,000
267
+ And then it does 123 transaction.
268
+
269
+ 68
270
+ 00:04:15,000 --> 00:04:16,000
271
+ And it.
272
+
273
+ 69
274
+ 00:04:17,000 --> 00:04:18,000
275
+ And it gets a hash.
276
+
277
+ 70
278
+ 00:04:18,000 --> 00:04:20,000
279
+ Now this is great.
280
+
281
+ 71
282
+ 00:04:20,000 --> 00:04:21,000
283
+ Why is this good?
284
+
285
+ 72
286
+ 00:04:21,000 --> 00:04:22,000
287
+ This is a blockchain.
288
+
289
+ 73
290
+ 00:04:22,000 --> 00:04:25,000
291
+ If you ever wanted to know what exactly is a blockchain, this is how it works.
292
+
293
+ 74
294
+ 00:04:25,000 --> 00:04:26,000
295
+ Why is this good?
296
+
297
+ 75
298
+ 00:04:26,000 --> 00:04:32,000
299
+ Because remember in the world of hashing, if anything changes, it changes all of the files within
300
+
301
+ 76
302
+ 00:04:32,000 --> 00:04:33,000
303
+ it, right?
304
+
305
+ 77
306
+ 00:04:33,000 --> 00:04:37,000
307
+ If anything changes, if if anything changes in the transaction, the hash will change.
308
+
309
+ 78
310
+ 00:04:37,000 --> 00:04:39,000
311
+ This is a this is a great technology.
312
+
313
+ 79
314
+ 00:04:39,000 --> 00:04:46,000
315
+ And the reason we do this is because if anyone ever manipulates a transaction, let's say any one of
316
+
317
+ 80
318
+ 00:04:46,000 --> 00:04:48,000
319
+ these first transaction.
320
+
321
+ 81
322
+ 00:04:49,000 --> 00:04:55,000
323
+ Then this hash will change, which will then invalidate this hash, which will then invalidate this
324
+
325
+ 82
326
+ 00:04:55,000 --> 00:04:56,000
327
+ hash.
328
+
329
+ 83
330
+ 00:04:56,000 --> 00:05:01,000
331
+ In other words, any time you manipulate a block, all the block that goes forward after that becomes
332
+
333
+ 84
334
+ 00:05:01,000 --> 00:05:02,000
335
+ invalidated.
336
+
337
+ 85
338
+ 00:05:03,000 --> 00:05:04,000
339
+ And here's a pretty cool part.
340
+
341
+ 86
342
+ 00:05:05,000 --> 00:05:12,000
343
+ This ledger, this block chain, these lists of blocks or all these blocks are stored across thousands
344
+
345
+ 87
346
+ 00:05:12,000 --> 00:05:14,000
347
+ of machines across your network.
348
+
349
+ 88
350
+ 00:05:14,000 --> 00:05:16,000
351
+ They all have the exact same ledger.
352
+
353
+ 89
354
+ 00:05:16,000 --> 00:05:19,000
355
+ So when somebody manipulates this one, they'll be able to tell, hey, you know what?
356
+
357
+ 90
358
+ 00:05:19,000 --> 00:05:21,000
359
+ That ledger is different than my ledger.
360
+
361
+ 91
362
+ 00:05:21,000 --> 00:05:22,000
363
+ What's the difference here?
364
+
365
+ 92
366
+ 00:05:22,000 --> 00:05:24,000
367
+ So it's decentralized.
368
+
369
+ 93
370
+ 00:05:24,000 --> 00:05:27,000
371
+ Decentralized means it's not stored on a single machine.
372
+
373
+ 94
374
+ 00:05:27,000 --> 00:05:29,000
375
+ In fact, it's stored on tons of machines.
376
+
377
+ 95
378
+ 00:05:29,000 --> 00:05:33,000
379
+ If anybody ever does a manipulation, it updates all the ledgers, and people are going to see.
380
+
381
+ 96
382
+ 00:05:33,000 --> 00:05:39,000
383
+ Well, technically, the only blocks that should ever be manipulated is this block four.
384
+
385
+ 97
386
+ 00:05:39,000 --> 00:05:40,000
387
+ Then block five.
388
+
389
+ 98
390
+ 00:05:40,000 --> 00:05:43,000
391
+ If anybody is changing blocks 2 or 3, that's a problem.
392
+
393
+ 99
394
+ 00:05:43,000 --> 00:05:45,000
395
+ So that's the concept of a blockchain.
396
+
397
+ 100
398
+ 00:05:45,000 --> 00:05:51,000
399
+ Now one thing that you may see pop up on your exam is a firm we call an open public ledger.
400
+
401
+ 101
402
+ 00:05:52,000 --> 00:05:54,000
403
+ This is a decentralized and transparent record.
404
+
405
+ 102
406
+ 00:05:54,000 --> 00:05:58,000
407
+ Keeping the ledger is accessible to anyone provides a permanent record of all transactions.
408
+
409
+ 103
410
+ 00:05:58,000 --> 00:06:05,000
411
+ Now, there are websites out there that has all of the crypto currency transaction.
412
+
413
+ 104
414
+ 00:06:05,000 --> 00:06:09,000
415
+ So if you ever find somebody who's cryptocurrency number.
416
+
417
+ 105
418
+ 00:06:11,000 --> 00:06:16,000
419
+ Uh, you can actually put it into the public ledger, and the ledger is going to show you all the transactions
420
+
421
+ 106
422
+ 00:06:16,000 --> 00:06:17,000
423
+ against that.
424
+
425
+ 107
426
+ 00:06:17,000 --> 00:06:25,000
427
+ So all the transactions that you take, utilize in a particular cryptocurrency is public to everyone.
428
+
429
+ 108
430
+ 00:06:25,000 --> 00:06:29,000
431
+ So they could see that this was used to purchase this, this and this was used in these transactions,
432
+
433
+ 109
434
+ 00:06:29,000 --> 00:06:30,000
435
+ but they don't know who owns it.
436
+
437
+ 110
438
+ 00:06:31,000 --> 00:06:34,000
439
+ So that is what a public ledger is.
440
+
441
+ 111
442
+ 00:06:35,000 --> 00:06:42,000
443
+ Once again, keep in mind that, uh, blockchains is not something unique only to cryptocurrency.
444
+
445
+ 112
446
+ 00:06:42,000 --> 00:06:46,000
447
+ Although it was pretty much invented with crypto, the creation of Bitcoin, it's not being utilized
448
+
449
+ 113
450
+ 00:06:46,000 --> 00:06:50,000
451
+ in tons of applications, so make sure you're familiar with it.
452
+
453
+ 114
454
+ 00:06:50,000 --> 00:06:51,000
455
+ It's all about integrity.
456
+
457
+ 115
458
+ 00:06:51,000 --> 00:06:58,000
459
+ Public ledgers, especially blockchains, is not about confidentiality because technically in a public
460
+
461
+ 116
462
+ 00:06:58,000 --> 00:06:59,000
463
+ ledger, it's all available.
464
+
465
+ 117
466
+ 00:06:59,000 --> 00:07:01,000
467
+ The big key word there is integrity.
468
+
469
+ 118
470
+ 00:07:01,000 --> 00:07:06,000
471
+ That means that if anybody manipulates any transaction on the blockchain, you're going to be able to
472
+
473
+ 119
474
+ 00:07:06,000 --> 00:07:12,000
475
+ detect it, making it one of the best technologies, best in upcoming technologies going forward.
476
+
07 - Cryptography/023 Salting OB 1.4_en.srt ADDED
@@ -0,0 +1,352 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ One of the worst technologies that still exists today that secures almost all the data on the planet
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:07,000
7
+ is passwords.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:08,000
11
+ Oh, I hate passwords.
12
+
13
+ 4
14
+ 00:00:08,000 --> 00:00:10,000
15
+ There's so many passwords to remember.
16
+
17
+ 5
18
+ 00:00:10,000 --> 00:00:16,000
19
+ You always got to remember a complex password, and then it's easily hacked unless we salt it.
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:20,000
23
+ In this video, I want to talk about a topic called Sultan.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:24,000
27
+ And Sultan is predominantly used to secure passwords.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:29,000
31
+ Now, I do have a link in an article we're going to look at on Wikipedia that really shows in depth
32
+
33
+ 9
34
+ 00:00:29,000 --> 00:00:30,000
35
+ salt.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:33,000
39
+ And I want to explain this to you guys, but what exactly is it?
40
+
41
+ 11
42
+ 00:00:33,000 --> 00:00:37,000
43
+ So Sultan is used to enhance the security of stored passwords.
44
+
45
+ 12
46
+ 00:00:37,000 --> 00:00:38,000
47
+ It involves listen carefully.
48
+
49
+ 13
50
+ 00:00:38,000 --> 00:00:47,000
51
+ Add in a unique random string of characters known as a salt to each password before it's hashed.
52
+
53
+ 14
54
+ 00:00:47,000 --> 00:00:50,000
55
+ Now, in order to move on, you got to understand something.
56
+
57
+ 15
58
+ 00:00:50,000 --> 00:00:54,000
59
+ When you store a password, a computer does not store the plaintext.
60
+
61
+ 16
62
+ 00:00:54,000 --> 00:00:58,000
63
+ So if your password is password one, two, three, it doesn't store password 123.
64
+
65
+ 17
66
+ 00:00:58,000 --> 00:01:00,000
67
+ It stores the hash of that.
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:02,000
71
+ Now remember I showed you guys hashing.
72
+
73
+ 19
74
+ 00:01:03,000 --> 00:01:05,000
75
+ So it will store just the hash value.
76
+
77
+ 20
78
+ 00:01:05,000 --> 00:01:12,000
79
+ When you come back to type in your password, it just you type in password one, two, three then hashes
80
+
81
+ 21
82
+ 00:01:12,000 --> 00:01:14,000
83
+ it and compare it to the hash it has.
84
+
85
+ 22
86
+ 00:01:14,000 --> 00:01:16,000
87
+ If it matches up boom, it logs you in.
88
+
89
+ 23
90
+ 00:01:16,000 --> 00:01:17,000
91
+ That's the normal operation.
92
+
93
+ 24
94
+ 00:01:17,000 --> 00:01:20,000
95
+ But how does Sultan work?
96
+
97
+ 25
98
+ 00:01:20,000 --> 00:01:23,000
99
+ Well, I have the process listed here.
100
+
101
+ 26
102
+ 00:01:24,000 --> 00:01:26,000
103
+ Okay, in case you're reading this at a later time.
104
+
105
+ 27
106
+ 00:01:27,000 --> 00:01:32,000
107
+ Uh, but I want to go to this article, uh, on Wikipedia, and I want to show it to you, actually,
108
+
109
+ 28
110
+ 00:01:32,000 --> 00:01:34,000
111
+ uh, more and more in practice.
112
+
113
+ 29
114
+ 00:01:34,000 --> 00:01:39,000
115
+ So let's go to that link that you see on the slide.
116
+
117
+ 30
118
+ 00:01:39,000 --> 00:01:40,000
119
+ Um.
120
+
121
+ 31
122
+ 00:01:41,000 --> 00:01:43,000
123
+ And here we go.
124
+
125
+ 32
126
+ 00:01:44,000 --> 00:01:47,000
127
+ Okay, so here's the link I just put on the slide there.
128
+
129
+ 33
130
+ 00:01:47,000 --> 00:01:48,000
131
+ And this is going to be Sultan.
132
+
133
+ 34
134
+ 00:01:48,000 --> 00:01:50,000
135
+ Now I want to show you guys a couple of things.
136
+
137
+ 35
138
+ 00:01:50,000 --> 00:01:51,000
139
+ First of all.
140
+
141
+ 36
142
+ 00:01:53,000 --> 00:01:55,000
143
+ So here is user one.
144
+
145
+ 37
146
+ 00:01:55,000 --> 00:01:57,000
147
+ This is their password.
148
+
149
+ 38
150
+ 00:01:57,000 --> 00:01:59,000
151
+ This is the hash of their password.
152
+
153
+ 39
154
+ 00:02:00,000 --> 00:02:00,000
155
+ Okay.
156
+
157
+ 40
158
+ 00:02:00,000 --> 00:02:01,000
159
+ That's the.
160
+
161
+ 41
162
+ 00:02:01,000 --> 00:02:05,000
163
+ This is the 256 bit hash that's generated by Sha 256.
164
+
165
+ 42
166
+ 00:02:06,000 --> 00:02:15,000
167
+ What the computer does with Sultan is that instead of just having the hash of just this password, what
168
+
169
+ 43
170
+ 00:02:15,000 --> 00:02:17,000
171
+ the computer does is that it generates a salt.
172
+
173
+ 44
174
+ 00:02:17,000 --> 00:02:22,000
175
+ This thing, it's a random set of a string of characters.
176
+
177
+ 45
178
+ 00:02:22,000 --> 00:02:28,000
179
+ What it does now is that it will append this to your password.
180
+
181
+ 46
182
+ 00:02:29,000 --> 00:02:31,000
183
+ Notice this is your password 123.
184
+
185
+ 47
186
+ 00:02:32,000 --> 00:02:36,000
187
+ And then it appends all this random stuff to it and then hashes this.
188
+
189
+ 48
190
+ 00:02:38,000 --> 00:02:41,000
191
+ Ash is all the things I just highlighted to form this.
192
+
193
+ 49
194
+ 00:02:41,000 --> 00:02:46,000
195
+ So what's stored in the computer's password file is not this hash of password one, two, three.
196
+
197
+ 50
198
+ 00:02:46,000 --> 00:02:47,000
199
+ It's this thing.
200
+
201
+ 51
202
+ 00:02:47,000 --> 00:02:51,000
203
+ And this is incredibly difficult to crack.
204
+
205
+ 52
206
+ 00:02:51,000 --> 00:02:54,000
207
+ Very few brute force in modern time will ever crack this.
208
+
209
+ 53
210
+ 00:02:54,000 --> 00:02:57,000
211
+ Look how long this is, and look how complex it is.
212
+
213
+ 54
214
+ 00:02:58,000 --> 00:03:05,000
215
+ So what it does is that it will take your password, append the salt, then hash it and then store it.
216
+
217
+ 55
218
+ 00:03:06,000 --> 00:03:11,000
219
+ When you come to log in, the verification process would be you type in password one, two, three.
220
+
221
+ 56
222
+ 00:03:11,000 --> 00:03:12,000
223
+ You never know assault.
224
+
225
+ 57
226
+ 00:03:12,000 --> 00:03:13,000
227
+ You type in password 123.
228
+
229
+ 58
230
+ 00:03:13,000 --> 00:03:19,000
231
+ It then re appends the salt, rehashes it and see oh okay.
232
+
233
+ 59
234
+ 00:03:19,000 --> 00:03:20,000
235
+ Does it match what they have?
236
+
237
+ 60
238
+ 00:03:20,000 --> 00:03:21,000
239
+ Yes okay.
240
+
241
+ 61
242
+ 00:03:21,000 --> 00:03:22,000
243
+ It's correct.
244
+
245
+ 62
246
+ 00:03:22,000 --> 00:03:27,000
247
+ Now if you're wondering does this really increase the security?
248
+
249
+ 63
250
+ 00:03:27,000 --> 00:03:29,000
251
+ The answer is absolutely.
252
+
253
+ 64
254
+ 00:03:31,000 --> 00:03:36,000
255
+ You see, one of the things here we have to remember, some people say, well, if I come to the prompt
256
+
257
+ 65
258
+ 00:03:36,000 --> 00:03:38,000
259
+ and I keep typing in the past one, it might crack it.
260
+
261
+ 66
262
+ 00:03:38,000 --> 00:03:44,000
263
+ You see, the way they crack password is they steal the hash, and then they run a brute force attack
264
+
265
+ 67
266
+ 00:03:44,000 --> 00:03:45,000
267
+ against the hash.
268
+
269
+ 68
270
+ 00:03:45,000 --> 00:03:49,000
271
+ No one knows your password except your head, except your brain.
272
+
273
+ 69
274
+ 00:03:49,000 --> 00:03:51,000
275
+ But they know the hash.
276
+
277
+ 70
278
+ 00:03:51,000 --> 00:03:54,000
279
+ The hash is technically not that difficult to get.
280
+
281
+ 71
282
+ 00:03:54,000 --> 00:03:58,000
283
+ And if they get a hash that has a whole bunch of random string of character, what they're going to
284
+
285
+ 72
286
+ 00:03:58,000 --> 00:04:00,000
287
+ do is they're going to brute force that hash.
288
+
289
+ 73
290
+ 00:04:00,000 --> 00:04:04,000
291
+ And even if they guess the hash, that's technically not your password because your password is one,
292
+
293
+ 74
294
+ 00:04:04,000 --> 00:04:05,000
295
+ two, three.
296
+
297
+ 75
298
+ 00:04:05,000 --> 00:04:13,000
299
+ So if they use a massive super alien machine to crack that hash and find out your password with the
300
+
301
+ 76
302
+ 00:04:13,000 --> 00:04:15,000
303
+ salt, it's not your password.
304
+
305
+ 77
306
+ 00:04:15,000 --> 00:04:16,000
307
+ Because you know what?
308
+
309
+ 78
310
+ 00:04:16,000 --> 00:04:21,000
311
+ When they type in your password, which they believe is your password, one, two, three plus the salt
312
+
313
+ 79
314
+ 00:04:21,000 --> 00:04:24,000
315
+ is then going to re append the old salt.
316
+
317
+ 80
318
+ 00:04:25,000 --> 00:04:26,000
319
+ And it's never going to work.
320
+
321
+ 81
322
+ 00:04:26,000 --> 00:04:35,000
323
+ Sultan, remember, drastically improves your passwords, drastically improves the password.
324
+
325
+ 82
326
+ 00:04:35,000 --> 00:04:37,000
327
+ Now you have to set this up.
328
+
329
+ 83
330
+ 00:04:37,000 --> 00:04:43,000
331
+ Sultan is done in many applications and web applications especially will utilize Sultan.
332
+
333
+ 84
334
+ 00:04:43,000 --> 00:04:47,000
335
+ So Sultan is an important topic in the world of IT security.
336
+
337
+ 85
338
+ 00:04:47,000 --> 00:04:53,000
339
+ Anytime you hear someone do or build in a web application, ask them will the password be salted?
340
+
341
+ 86
342
+ 00:04:53,000 --> 00:04:56,000
343
+ If not as an IT security security professional?
344
+
345
+ 87
346
+ 00:04:56,000 --> 00:05:01,000
347
+ Tell them, I would highly recommend you salt the password.
348
+
349
+ 88
350
+ 00:05:01,000 --> 00:05:04,000
351
+ That way the system is super secure.
352
+
07 - Cryptography/024 TPM OB 1.4_en.srt ADDED
@@ -0,0 +1,284 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ One of the most dangerous things that can ever happen in the world of it is when you're a security administrator
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:12,000
7
+ and you get a call that one of your employee has lost their laptop, because on this laptop contains
8
+
9
+ 3
10
+ 00:00:12,000 --> 00:00:18,000
11
+ all the company's data, all that person's email, it doesn't matter how secure their password is.
12
+
13
+ 4
14
+ 00:00:18,000 --> 00:00:23,000
15
+ You see, if I want the data off of this laptop, I don't need to know your password.
16
+
17
+ 5
18
+ 00:00:23,000 --> 00:00:31,000
19
+ All I got to do unscrew the bottom, take out the bottom, take out the hard drive, take that hard
20
+
21
+ 6
22
+ 00:00:31,000 --> 00:00:33,000
23
+ drive and mount it to my computer.
24
+
25
+ 7
26
+ 00:00:33,000 --> 00:00:36,000
27
+ Whether it's a Sata drive Mdot, it doesn't matter.
28
+
29
+ 8
30
+ 00:00:36,000 --> 00:00:38,000
31
+ I'm just going to plug the drive into my machine.
32
+
33
+ 9
34
+ 00:00:38,000 --> 00:00:44,000
35
+ And there's a lot of external Mdot two and Sata connectors and whatever I can use to externally mount
36
+
37
+ 10
38
+ 00:00:44,000 --> 00:00:47,000
39
+ your hard drive onto my desktop.
40
+
41
+ 11
42
+ 00:00:47,000 --> 00:00:51,000
43
+ And now I can open all the files on your hard drive.
44
+
45
+ 12
46
+ 00:00:51,000 --> 00:00:53,000
47
+ I don't care about logging into your windows.
48
+
49
+ 13
50
+ 00:00:53,000 --> 00:00:55,000
51
+ All I want to do is steal your data.
52
+
53
+ 14
54
+ 00:00:55,000 --> 00:01:00,000
55
+ This is a nightmare scenario for any it department.
56
+
57
+ 15
58
+ 00:01:00,000 --> 00:01:03,000
59
+ So what do we do with devices like this?
60
+
61
+ 16
62
+ 00:01:03,000 --> 00:01:05,000
63
+ Or god forbid, even more devices like this?
64
+
65
+ 17
66
+ 00:01:05,000 --> 00:01:11,000
67
+ You see, especially when it comes to computers like this, we need to do what is called hard drive
68
+
69
+ 18
70
+ 00:01:11,000 --> 00:01:12,000
71
+ encryption.
72
+
73
+ 19
74
+ 00:01:13,000 --> 00:01:16,000
75
+ We need to encrypt the hard drive.
76
+
77
+ 20
78
+ 00:01:16,000 --> 00:01:21,000
79
+ That way, if anybody does what I just say, I've taken the hard drive out, mounted it to a machine,
80
+
81
+ 21
82
+ 00:01:21,000 --> 00:01:24,000
83
+ and seeing all the files in it, they won't be able to see anything.
84
+
85
+ 22
86
+ 00:01:24,000 --> 00:01:26,000
87
+ Because the drive is encrypted.
88
+
89
+ 23
90
+ 00:01:26,000 --> 00:01:28,000
91
+ The drive has to be encrypted.
92
+
93
+ 24
94
+ 00:01:28,000 --> 00:01:30,000
95
+ This is called disk encryption.
96
+
97
+ 25
98
+ 00:01:30,000 --> 00:01:38,000
99
+ And one of the ways of doing that is by utilizing oops, a TPM or a TPM chip.
100
+
101
+ 26
102
+ 00:01:38,000 --> 00:01:44,000
103
+ A lot of these corporate laptops comes built with something we call a TPM chip.
104
+
105
+ 27
106
+ 00:01:45,000 --> 00:01:52,000
107
+ TPM Trusted Platform module is a hardware component designed to secure hardware by integrating cryptographic
108
+
109
+ 28
110
+ 00:01:52,000 --> 00:01:53,000
111
+ keys.
112
+
113
+ 29
114
+ 00:01:53,000 --> 00:01:59,000
115
+ It's basically a device, okay that allows the generation of storage of cryptographic keys.
116
+
117
+ 30
118
+ 00:01:59,000 --> 00:02:04,000
119
+ TPMs can generate encryption keys, keeping them private, keeping the private portion of these keys
120
+
121
+ 31
122
+ 00:02:04,000 --> 00:02:06,000
123
+ safe within a TPM chip itself.
124
+
125
+ 32
126
+ 00:02:07,000 --> 00:02:10,000
127
+ Now it's used for multiple purposes.
128
+
129
+ 33
130
+ 00:02:10,000 --> 00:02:14,000
131
+ Number one, it's used to do things like disk encryption.
132
+
133
+ 34
134
+ 00:02:14,000 --> 00:02:16,000
135
+ Now if you have windows.
136
+
137
+ 35
138
+ 00:02:17,000 --> 00:02:19,000
139
+ Windows 11, and so on.
140
+
141
+ 36
142
+ 00:02:19,000 --> 00:02:24,000
143
+ Windows 10 11, the higher versions of it, the business editions of it, you can have BitLocker, like
144
+
145
+ 37
146
+ 00:02:24,000 --> 00:02:26,000
147
+ I have BitLocker on this machine.
148
+
149
+ 38
150
+ 00:02:26,000 --> 00:02:28,000
151
+ I also have BitLocker on this machine.
152
+
153
+ 39
154
+ 00:02:28,000 --> 00:02:31,000
155
+ You turn on BitLocker encryption.
156
+
157
+ 40
158
+ 00:02:31,000 --> 00:02:37,000
159
+ And what BitLocker does if the machine has a TPM chip, is that it will encrypt the hard drive and it'll
160
+
161
+ 41
162
+ 00:02:37,000 --> 00:02:40,000
163
+ store the cryptographic keys on the TPM chip.
164
+
165
+ 42
166
+ 00:02:40,000 --> 00:02:46,000
167
+ If you remove the hard drive, you wouldn't be able to see anything because you'll need to decrypt it.
168
+
169
+ 43
170
+ 00:02:46,000 --> 00:02:50,000
171
+ But the cryptographic keys is on the TPM chip.
172
+
173
+ 44
174
+ 00:02:50,000 --> 00:02:53,000
175
+ Now, the TPM chip will be like something that's sorted into the motherboard.
176
+
177
+ 45
178
+ 00:02:53,000 --> 00:02:56,000
179
+ It wouldn't be able something you could just rip off.
180
+
181
+ 46
182
+ 00:02:57,000 --> 00:03:02,000
183
+ The TPM can also store and manage keys using the process of verifying the boot process.
184
+
185
+ 47
186
+ 00:03:02,000 --> 00:03:06,000
187
+ That way no malware can try to load up in the boot process.
188
+
189
+ 48
190
+ 00:03:06,000 --> 00:03:10,000
191
+ So TPM is super important right now.
192
+
193
+ 49
194
+ 00:03:10,000 --> 00:03:13,000
195
+ If you're managing an IT department, you must.
196
+
197
+ 50
198
+ 00:03:13,000 --> 00:03:21,000
199
+ And I say you must ensure that all your laptops especially have TPM, anything that's mobile.
200
+
201
+ 51
202
+ 00:03:22,000 --> 00:03:25,000
203
+ So exactly what is it?
204
+
205
+ 52
206
+ 00:03:25,000 --> 00:03:30,000
207
+ Well, it's basically it's a secure it has what's called a crypto processor that's designed to carry
208
+
209
+ 53
210
+ 00:03:30,000 --> 00:03:32,000
211
+ out cryptographic operations.
212
+
213
+ 54
214
+ 00:03:32,000 --> 00:03:39,000
215
+ The primary purpose of it, once again, is to ensure that we create cryptographic keys to keep our
216
+
217
+ 55
218
+ 00:03:39,000 --> 00:03:40,000
219
+ disk secure.
220
+
221
+ 56
222
+ 00:03:40,000 --> 00:03:45,000
223
+ This is going to be the two main beneficial aspects of a TPM chip.
224
+
225
+ 57
226
+ 00:03:45,000 --> 00:03:47,000
227
+ I can't emphasize this enough.
228
+
229
+ 58
230
+ 00:03:47,000 --> 00:03:48,000
231
+ One time.
232
+
233
+ 59
234
+ 00:03:49,000 --> 00:03:55,000
235
+ Now this actually, this laptop actually has, uh, a TPM chip.
236
+
237
+ 60
238
+ 00:03:55,000 --> 00:03:56,000
239
+ It is fully encrypted.
240
+
241
+ 61
242
+ 00:03:56,000 --> 00:04:01,000
243
+ It does have the data of the business on it because it has my email and I am the CEO of the business.
244
+
245
+ 62
246
+ 00:04:01,000 --> 00:04:03,000
247
+ It has my email, it has work I'm working on.
248
+
249
+ 63
250
+ 00:04:04,000 --> 00:04:06,000
251
+ And one time I left it in the back of an Uber.
252
+
253
+ 64
254
+ 00:04:07,000 --> 00:04:09,000
255
+ And you know, it didn't bother me much.
256
+
257
+ 65
258
+ 00:04:09,000 --> 00:04:12,000
259
+ I called the Uber like the moment I figured out I left it.
260
+
261
+ 66
262
+ 00:04:12,000 --> 00:04:17,000
263
+ It didn't like my heart didn't sink because I realized, well, even if somebody steals this laptop.
264
+
265
+ 67
266
+ 00:04:18,000 --> 00:04:20,000
267
+ My password is super secure.
268
+
269
+ 68
270
+ 00:04:20,000 --> 00:04:23,000
271
+ They probably not be able to get in, but if they do take the hard drive out.
272
+
273
+ 69
274
+ 00:04:24,000 --> 00:04:28,000
275
+ They'll never get anything out of it, because the TPM in which obviously the laptop is back with me,
276
+
277
+ 70
278
+ 00:04:28,000 --> 00:04:30,000
279
+ I called Uber and the driver dropped it back.
280
+
281
+ 71
282
+ 00:04:30,000 --> 00:04:35,000
283
+ So make sure you use TPM chips, especially on all mobile devices.
284
+
07 - Cryptography/025 Secure Enclave OB 1.4_en.srt ADDED
@@ -0,0 +1,124 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When a computer is processing data, one of the things that the computer must be able to do, especially
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:09,000
7
+ secure processing, is that it has to be able to like segment that off.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:16,000
11
+ You don't want things like processing of thumbprints or passwords to just be in any place of memory.
12
+
13
+ 4
14
+ 00:00:16,000 --> 00:00:21,000
15
+ We have this concept called a secure enclave.
16
+
17
+ 5
18
+ 00:00:21,000 --> 00:00:25,000
19
+ This provides a highly secure space within a device.
20
+
21
+ 6
22
+ 00:00:25,000 --> 00:00:29,000
23
+ Memory, where sensitive data can be stored in cryptographic operations is done on.
24
+
25
+ 7
26
+ 00:00:29,000 --> 00:00:33,000
27
+ And this basically isolates it from the other operating systems and processes.
28
+
29
+ 8
30
+ 00:00:33,000 --> 00:00:35,000
31
+ Why would you do this?
32
+
33
+ 9
34
+ 00:00:35,000 --> 00:00:43,000
35
+ Well, cryptographic processes generally in things does things like encrypt and decrypt sensitive data.
36
+
37
+ 10
38
+ 00:00:43,000 --> 00:00:48,000
39
+ It checks things like passwords or facial recognition or biometrics.
40
+
41
+ 11
42
+ 00:00:48,000 --> 00:00:51,000
43
+ You don't want this to just be in any part of a computer memory.
44
+
45
+ 12
46
+ 00:00:51,000 --> 00:00:51,000
47
+ Why?
48
+
49
+ 13
50
+ 00:00:51,000 --> 00:00:55,000
51
+ Because then other programs can read it and steal that data.
52
+
53
+ 14
54
+ 00:00:55,000 --> 00:01:01,000
55
+ So what we do is we set up secure enclaves, and this is going to be done within the actual software
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:02,000
59
+ and hardware.
60
+
61
+ 16
62
+ 00:01:03,000 --> 00:01:04,000
63
+ So what does it do?
64
+
65
+ 17
66
+ 00:01:04,000 --> 00:01:10,000
67
+ Well, it ensures that sensitive data, like fingerprints, is stored in an environment that is separated,
68
+
69
+ 18
70
+ 00:01:10,000 --> 00:01:12,000
71
+ segregated from the rest of the operating system.
72
+
73
+ 19
74
+ 00:01:12,000 --> 00:01:14,000
75
+ This protects it from any malware.
76
+
77
+ 20
78
+ 00:01:14,000 --> 00:01:19,000
79
+ So let's say you don't even know you have malicious software in your machine.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:25,000
83
+ So you try to decode a file or log in with something, let's say a thumbprint.
84
+
85
+ 22
86
+ 00:01:26,000 --> 00:01:30,000
87
+ Well, you don't really have to worry too much about the malware getting it, because you're using this
88
+
89
+ 23
90
+ 00:01:30,000 --> 00:01:33,000
91
+ concept on your operating system and on your hardware.
92
+
93
+ 24
94
+ 00:01:34,000 --> 00:01:39,000
95
+ Some of the key features, basically hardware isolation, the data and operations with data are isolated
96
+
97
+ 25
98
+ 00:01:39,000 --> 00:01:42,000
99
+ at the hardware level, so software can't break it.
100
+
101
+ 26
102
+ 00:01:42,000 --> 00:01:47,000
103
+ It limits access and is generally considered tamper resistant, making physical attacks very difficult
104
+
105
+ 27
106
+ 00:01:47,000 --> 00:01:50,000
107
+ to get it on high secure systems.
108
+
109
+ 28
110
+ 00:01:50,000 --> 00:01:56,000
111
+ This is one of the things you're going to have to make sure is built into the system, because you could
112
+
113
+ 29
114
+ 00:01:56,000 --> 00:02:02,000
115
+ have malware or malicious software on your machine and not know it, and then secure operations could
116
+
117
+ 30
118
+ 00:02:02,000 --> 00:02:04,000
119
+ be taking place in the malware can be stealing it.
120
+
121
+ 31
122
+ 00:02:04,000 --> 00:02:08,000
123
+ But if you use a secure enclave, that is much less likely to happen.
124
+
07 - Cryptography/026 Obfuscation OB 1.4_en.srt ADDED
@@ -0,0 +1,252 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ Sometimes when you are playing around with data or have to have test data, you have to be careful because
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:09,000
7
+ a lot of data in the business is considered confidential.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:13,000
11
+ But sometimes when you're building an application, you need data to work with.
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:16,000
15
+ You need large data sets to actually work with.
16
+
17
+ 5
18
+ 00:00:16,000 --> 00:00:22,000
19
+ Now in this video, I want to show you guys a topic we're going to refer to as data obfuscation.
20
+
21
+ 6
22
+ 00:00:22,000 --> 00:00:28,000
23
+ Obfuscation is basically the process of disguising sensitive, confidential or sensitive data protected
24
+
25
+ 7
26
+ 00:00:28,000 --> 00:00:30,000
27
+ basically from unauthorized access.
28
+
29
+ 8
30
+ 00:00:30,000 --> 00:00:32,000
31
+ Now I'm going to try this.
32
+
33
+ 9
34
+ 00:00:32,000 --> 00:00:32,000
35
+ Here.
36
+
37
+ 10
38
+ 00:00:32,000 --> 00:00:35,000
39
+ We have another video coming up on tokenization.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:38,000
43
+ But I'm going to I want to show you guys what obfuscation is going to do.
44
+
45
+ 12
46
+ 00:00:39,000 --> 00:00:42,000
47
+ And I'm going to go to that link and I want to show you guys what it does.
48
+
49
+ 13
50
+ 00:00:42,000 --> 00:00:45,000
51
+ So basically it's going to hide the data.
52
+
53
+ 14
54
+ 00:00:45,000 --> 00:00:51,000
55
+ Let's say you're writing a program like your source code to the program in order to make it difficult
56
+
57
+ 15
58
+ 00:00:51,000 --> 00:00:53,000
59
+ for people to find the original source code.
60
+
61
+ 16
62
+ 00:00:53,000 --> 00:00:57,000
63
+ If they see the source code they decompile the program is you can obfuscate it.
64
+
65
+ 17
66
+ 00:00:57,000 --> 00:00:58,000
67
+ Let me show you guys what it looks like.
68
+
69
+ 18
70
+ 00:00:58,000 --> 00:01:02,000
71
+ So if you follow that link in this slide there, this is what you would have gotten.
72
+
73
+ 19
74
+ 00:01:02,000 --> 00:01:07,000
75
+ And here's this is a JavaScript Obfuscator tool.
76
+
77
+ 20
78
+ 00:01:07,000 --> 00:01:15,000
79
+ And you notice that this is this is basically just the JavaScript that when ran it just says hello world.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:18,000
83
+ It's the first thing you learn when you learn JavaScript or Java in general.
84
+
85
+ 22
86
+ 00:01:18,000 --> 00:01:22,000
87
+ This is a comment that says paste your JavaScript code here.
88
+
89
+ 23
90
+ 00:01:22,000 --> 00:01:24,000
91
+ Now this is going to obfuscate it.
92
+
93
+ 24
94
+ 00:01:24,000 --> 00:01:25,000
95
+ So you can use this.
96
+
97
+ 25
98
+ 00:01:25,000 --> 00:01:28,000
99
+ You can actually put your code in here if you write code and obfuscate it.
100
+
101
+ 26
102
+ 00:01:28,000 --> 00:01:30,000
103
+ So if I say obfuscate watch what happens.
104
+
105
+ 27
106
+ 00:01:30,000 --> 00:01:33,000
107
+ Ooh, that looks kind of crazy doesn't it?
108
+
109
+ 28
110
+ 00:01:33,000 --> 00:01:37,000
111
+ Now if you run this code.
112
+
113
+ 29
114
+ 00:01:38,000 --> 00:01:38,000
115
+ Okay.
116
+
117
+ 30
118
+ 00:01:38,000 --> 00:01:44,000
119
+ If you run this code, it will run the code that we saw here.
120
+
121
+ 31
122
+ 00:01:44,000 --> 00:01:49,000
123
+ This output obfuscated code technically is this.
124
+
125
+ 32
126
+ 00:01:49,000 --> 00:01:54,000
127
+ Except as you notice, it looks kind of crazy.
128
+
129
+ 33
130
+ 00:01:56,000 --> 00:01:56,000
131
+ It's obfuscate that.
132
+
133
+ 34
134
+ 00:01:57,000 --> 00:01:59,000
135
+ So it's actually all there.
136
+
137
+ 35
138
+ 00:01:59,000 --> 00:02:01,000
139
+ But it is difficult.
140
+
141
+ 36
142
+ 00:02:01,000 --> 00:02:04,000
143
+ It basically hides a lot of the code, but it's still usable.
144
+
145
+ 37
146
+ 00:02:05,000 --> 00:02:09,000
147
+ Now there are some other ways here that we can do.
148
+
149
+ 38
150
+ 00:02:09,000 --> 00:02:10,000
151
+ Obfuscation.
152
+
153
+ 39
154
+ 00:02:10,000 --> 00:02:14,000
155
+ What I showed you there is basically like a code code obfuscation, but it tells you the principle that
156
+
157
+ 40
158
+ 00:02:14,000 --> 00:02:18,000
159
+ basically you're hiding your sensitive data.
160
+
161
+ 41
162
+ 00:02:18,000 --> 00:02:20,000
163
+ There are a couple of things here we want to talk about.
164
+
165
+ 42
166
+ 00:02:21,000 --> 00:02:22,000
167
+ First of all.
168
+
169
+ 43
170
+ 00:02:22,000 --> 00:02:23,000
171
+ Data masking.
172
+
173
+ 44
174
+ 00:02:23,000 --> 00:02:28,000
175
+ Data masking is when you create a substitute version of a data set.
176
+
177
+ 45
178
+ 00:02:28,000 --> 00:02:32,000
179
+ The values are changed, but the data but the format remains the same.
180
+
181
+ 46
182
+ 00:02:32,000 --> 00:02:36,000
183
+ An organization can run tests or training sessions if they were using real data.
184
+
185
+ 47
186
+ 00:02:36,000 --> 00:02:41,000
187
+ So let's say you have a let's say you made a financial application and you got to test how credit cards,
188
+
189
+ 48
190
+ 00:02:41,000 --> 00:02:44,000
191
+ you know, how much credit cards it can hold when instead of putting in real credit card numbers, just
192
+
193
+ 49
194
+ 00:02:44,000 --> 00:02:49,000
195
+ take the take the actual credit card number and create a different version of it that's not real, and
196
+
197
+ 50
198
+ 00:02:49,000 --> 00:02:50,000
199
+ then use that data.
200
+
201
+ 51
202
+ 00:02:50,000 --> 00:02:50,000
203
+ Masking.
204
+
205
+ 52
206
+ 00:02:51,000 --> 00:02:56,000
207
+ Encryption is something that we have spent an enormous amount of time in the encryption section on.
208
+
209
+ 53
210
+ 00:02:56,000 --> 00:03:00,000
211
+ So remember encryption will hide the meaning of information.
212
+
213
+ 54
214
+ 00:03:00,000 --> 00:03:01,000
215
+ It's part of what it does.
216
+
217
+ 55
218
+ 00:03:02,000 --> 00:03:05,000
219
+ The next thing you're going to want to be familiar with is called tokenization.
220
+
221
+ 56
222
+ 00:03:05,000 --> 00:03:09,000
223
+ Tokenization, depending on the exam you're taking, will be covered on your test.
224
+
225
+ 57
226
+ 00:03:09,000 --> 00:03:14,000
227
+ Tokenization creates tokens to represent certain data.
228
+
229
+ 58
230
+ 00:03:14,000 --> 00:03:16,000
231
+ Keep an eye on that door in the next video when I cover it.
232
+
233
+ 59
234
+ 00:03:17,000 --> 00:03:21,000
235
+ But obfuscation is something that is important there.
236
+
237
+ 60
238
+ 00:03:21,000 --> 00:03:25,000
239
+ They come up lots of times when you have to use sensitive data.
240
+
241
+ 61
242
+ 00:03:25,000 --> 00:03:30,000
243
+ You want to process sensitive data without actually having the sensitive data.
244
+
245
+ 62
246
+ 00:03:30,000 --> 00:03:31,000
247
+ You'll see what I mean next.
248
+
249
+ 63
250
+ 00:03:31,000 --> 00:03:32,000
251
+ Tokenization.
252
+