Add files using upload-large-folder tool
Browse filesThis view is limited to 50 files because it contains too many changes. See raw diff
- .gitattributes +31 -0
- 04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 +3 -0
- 05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/007 XSS OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 +3 -0
- 05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 +3 -0
- 06 - Signs of Attacks/001 Malware OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/002 Viruses OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/003 Worms OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/004 Trojans OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/006 Spyware OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/011 DDOS OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/012 DNS OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 +3 -0
- 07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt +852 -0
- 07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt +268 -0
- 07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt +488 -0
- 07 - Cryptography/011 Hashing OB 1.4_en.srt +1600 -0
- 07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt +240 -0
- 07 - Cryptography/013 Digital Signatures OB 1.4_en.srt +636 -0
- 07 - Cryptography/014 Intro to PKI OB 1.4_en.srt +124 -0
- 07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt +1176 -0
- 07 - Cryptography/017 PKI Process OB 1.4_en.srt +664 -0
- 07 - Cryptography/018 Certificates OB 1.4_en.srt +824 -0
- 07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt +220 -0
- 07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt +372 -0
- 07 - Cryptography/021 Steganography OB 1.4_en.srt +392 -0
- 07 - Cryptography/022 Blockchain OB 1.4_en.srt +476 -0
- 07 - Cryptography/023 Salting OB 1.4_en.srt +352 -0
- 07 - Cryptography/024 TPM OB 1.4_en.srt +284 -0
- 07 - Cryptography/025 Secure Enclave OB 1.4_en.srt +124 -0
- 07 - Cryptography/026 Obfuscation OB 1.4_en.srt +252 -0
.gitattributes
CHANGED
|
@@ -65,3 +65,34 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
|
|
| 65 |
04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 66 |
04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 67 |
04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 65 |
04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 66 |
04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 67 |
04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 68 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/001[[:space:]]Vulnerabilities[[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 69 |
+
04[[:space:]]-[[:space:]]Threats/009[[:space:]]Threat[[:space:]]Vectors[[:space:]]and[[:space:]]Attack[[:space:]]Surfaces[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 70 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/003[[:space:]]Race[[:space:]]Conditions[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 71 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/004[[:space:]]Malicious[[:space:]]Updates[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 72 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/002[[:space:]]Memory[[:space:]]injection[[:space:]]and[[:space:]]buffer[[:space:]]overflows[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 73 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/005[[:space:]]OS-Based[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 74 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/007[[:space:]]XSS[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 75 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/008[[:space:]]Hardware[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 76 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/006[[:space:]]SQL[[:space:]]Injections[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 77 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/009[[:space:]]VM[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 78 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/011[[:space:]]Supply[[:space:]]Chain[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 79 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/010[[:space:]]Cloud-specific[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 80 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/012[[:space:]]Cryptographic[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 81 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/013[[:space:]]Misconfiguration[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 82 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/014[[:space:]]Mobile[[:space:]]Device[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 83 |
+
05[[:space:]]-[[:space:]]Vulnerabilities/015[[:space:]]Zero-day[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 84 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/001[[:space:]]Malware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 85 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/002[[:space:]]Viruses[[:space:]][[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 86 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/004[[:space:]]Trojans[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 87 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/003[[:space:]]Worms[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 88 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/006[[:space:]]Spyware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 89 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/007[[:space:]]Rootkit[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 90 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/008[[:space:]]Logic[[:space:]]Bomb[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 91 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/005[[:space:]]Ransomware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 92 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/010[[:space:]]Bloatware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 93 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/009[[:space:]]Keyloggers[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 94 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/012[[:space:]]DNS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 95 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/013[[:space:]]Onpath[[:space:]]Attack[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 96 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 97 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 98 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:0ea8bb280b7aa00ee6e5ff91314a79037663623e7fc0b5bc46c28628bd17c02d
|
| 3 |
+
size 358178371
|
05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:cb6b5599cca6eea9c2736821187b2aca950a91ed895c076d4afa1a635fda33d4
|
| 3 |
+
size 51453967
|
05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:f68268c8a6df35545a34b6537ff1ae3457a4a8a1f3413909a541023c7c3533fe
|
| 3 |
+
size 303240221
|
05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:827629d12a9db8054ddd7bb753593d6cd2cd3395f43a6309f817875330c90f57
|
| 3 |
+
size 218816868
|
05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:224434b0ef6bdf7a0421decbf0ac02826ca27f1b0b631d052af6e86d3d65205a
|
| 3 |
+
size 69037281
|
05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:58c34142c72f36bd099bc2e9175544ef81586d217f9782088d54545c5f48c0ec
|
| 3 |
+
size 226457460
|
05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:eac89091ca6406c03551377c8688fd4f52d61ea836f83a9a88fca22983059eb0
|
| 3 |
+
size 408025612
|
05 - Vulnerabilities/007 XSS OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:1ebc247a98f8eb09c18681b79469de174d97f5b3bde93a4d44d1f383a772ef17
|
| 3 |
+
size 135683436
|
05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:7300861fccd624dcc80384ffec805620c4605fa31cd3435e4fca9f74433ce30d
|
| 3 |
+
size 175563789
|
05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:7ac9de70b4d06911c5960aa76d9d9e178d5fd0d57d42cf7c553f0df071456adc
|
| 3 |
+
size 89576988
|
05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:22e716b22c428835c49530cf3483a6b38b841fbc70b803e0055513dbb7c020f2
|
| 3 |
+
size 316842710
|
05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:09f04bddcaebb5f48817b818fe3db8c8df91a70cc8e1cf628d74965009d87964
|
| 3 |
+
size 269551046
|
05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:0d9d15aa0b12a658e8ccce53dd290c49c87091e21c64ecff4f22e24b404ceba7
|
| 3 |
+
size 198706946
|
05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:85c11b70fa06e0769ea994ff665d1bf07a2b0c03cdd67298bf1f2eb45b97c5fa
|
| 3 |
+
size 176934829
|
05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:0fbe44a5da82866917e877f6218b89d8453d1fcfae4552f30b87cc3935a1bfde
|
| 3 |
+
size 428914675
|
05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:12993189b8460e9f3acfed58036f5a19a4b20ef26605359d2fa858e4b3dd0009
|
| 3 |
+
size 180828460
|
06 - Signs of Attacks/001 Malware OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:b81cb76d342e2cf86c742e50cfcb7d13c031c85aa5ea688543554782e20aad07
|
| 3 |
+
size 35123665
|
06 - Signs of Attacks/002 Viruses OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:15d6f166dbb596a6b3bb9e2f6da2cbfed8b994740dfa98146fbaf91769413057
|
| 3 |
+
size 314530848
|
06 - Signs of Attacks/003 Worms OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:3e83018efbed549c09b383906c59a3c4460f03cff47704283c4c7888340fe6e9
|
| 3 |
+
size 216076980
|
06 - Signs of Attacks/004 Trojans OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:ebe35a406da737d6f80d67253e884141c0f52aee970099aa8425df24b1e6396a
|
| 3 |
+
size 156627975
|
06 - Signs of Attacks/005 Ransomware OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:cba44cc2f789d7f0f71483eae60d97a517b718f29d2817e5815b1a000bf425bd
|
| 3 |
+
size 249594928
|
06 - Signs of Attacks/006 Spyware OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:fa3bb793eb84c4f30d6036707ff90ef34fd5c478c7159cef46d5c268b09165df
|
| 3 |
+
size 142438065
|
06 - Signs of Attacks/007 Rootkit OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:a587afe5ed336a341348c0f88fedbf5a5f4d27cf8cfafb8899c085755d158695
|
| 3 |
+
size 154446570
|
06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:923d96eca9619dc8fd2982cdf24f4f9397626c36f5dd66cbc3386f2b91bbbc52
|
| 3 |
+
size 101035815
|
06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:2679df59b2c32e13cc3300549d25a8dc8a0d97f17800d367c74bd4193928ebc9
|
| 3 |
+
size 237412212
|
06 - Signs of Attacks/010 Bloatware OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:fac8a4f1ace9423b2a2c0dd5461d0e98c56c5ff76f77b0b051af18f59ee0fe9c
|
| 3 |
+
size 74555519
|
06 - Signs of Attacks/011 DDOS OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:69dcc08a90ce0d4cf044b01258d8e48b84c7e34b84bac088d57543d5579db03e
|
| 3 |
+
size 613421399
|
06 - Signs of Attacks/012 DNS OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:b612b9f273589d5f6721a35735ea5ed9fd8379f95084693b1b835e872681a8dc
|
| 3 |
+
size 483439518
|
06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:68088df41f07e4224ed283a402705a7a282be595a3658a10edb77010f1085c5c
|
| 3 |
+
size 285525484
|
06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:57f8c7337a266a61625b6f6b8cc1391a578baede810e98a3899df66a98ab58df
|
| 3 |
+
size 192202206
|
06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:521b6ee434ae5b7389c51416249182d8b4b6a8aead0235b28082f271380afcf2
|
| 3 |
+
size 176957870
|
07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,852 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:00,000
|
| 3 |
+
Okay.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:00,000 --> 00:00:02,000
|
| 7 |
+
So we just covered symmetric encryption.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:02,000 --> 00:00:08,000
|
| 11 |
+
And if you remember correctly the key to choosing to encrypt is the same key that's used to decrypt.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:08,000 --> 00:00:13,000
|
| 15 |
+
When in this video I want to take a deep dive into the concepts of asymmetric cryptography.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:13,000 --> 00:00:19,000
|
| 19 |
+
Now I briefly mentioned that asymmetric and symmetric combines together in a hybrid cryptography system
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:19,000 --> 00:00:21,000
|
| 23 |
+
to actually transport secure data.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:21,000 --> 00:00:23,000
|
| 27 |
+
So you actually.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:28,000
|
| 31 |
+
Can't really do secure communication today technically without asymmetric.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:28,000 --> 00:00:30,000
|
| 35 |
+
So let's get a deep dive into it.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:30,000 --> 00:00:32,000
|
| 39 |
+
But what exactly is it you see?
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:32,000 --> 00:00:33,000
|
| 43 |
+
Asymmetric encryption.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:33,000 --> 00:00:34,000
|
| 47 |
+
So the word symmetric means the same.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:34,000 --> 00:00:36,000
|
| 51 |
+
Asymmetric is going to mean different.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:37,000 --> 00:00:38,000
|
| 55 |
+
Is known.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:38,000 --> 00:00:43,000
|
| 59 |
+
First of all I want to mention is something we call public key cryptography.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:43,000 --> 00:00:43,000
|
| 63 |
+
All right.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:43,000 --> 00:00:45,000
|
| 67 |
+
Public key cryptography.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:45,000 --> 00:00:50,000
|
| 71 |
+
Now, keep in mind, if anybody ever says you read in any book, they say something like secret key
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:50,000 --> 00:00:53,000
|
| 75 |
+
cryptography or private key cryptography.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:00:53,000 --> 00:00:58,000
|
| 79 |
+
That is symmetric public key cryptography is asymmetric.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:00:59,000 --> 00:01:06,000
|
| 83 |
+
This is a cryptographic system that uses pairs of keys, a public key which is given out widely, and
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:06,000 --> 00:01:08,000
|
| 87 |
+
a private key which is only known to the users.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:08,000 --> 00:01:13,000
|
| 91 |
+
So everybody has two keys, a public key and a private key.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:13,000 --> 00:01:17,000
|
| 95 |
+
The public key encryption decrypts and it's given with anyone.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:17,000 --> 00:01:20,000
|
| 99 |
+
The private key can also encrypt and decrypt, and it's kept with the owner.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:20,000 --> 00:01:21,000
|
| 103 |
+
No one gets it.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:21,000 --> 00:01:26,000
|
| 107 |
+
Remember that everybody in the crypto system has two keys.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:26,000 --> 00:01:32,000
|
| 111 |
+
So for example, let's say I got me Mary and Bob.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:32,000 --> 00:01:33,000
|
| 115 |
+
Well easy.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:33,000 --> 00:01:35,000
|
| 119 |
+
I'm going to have a public private key.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:35,000 --> 00:01:37,000
|
| 123 |
+
Mary is going to have a public private key.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:37,000 --> 00:01:42,000
|
| 127 |
+
And Bob is going to have and Bob is going to have a public everybody has a public private key.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:42,000 --> 00:01:46,000
|
| 131 |
+
The way the encryption process works is different than symmetric and symmetric.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:46,000 --> 00:01:50,000
|
| 135 |
+
I generate the data, I generate the key I encrypted, give them the data, give them the key.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:50,000 --> 00:01:51,000
|
| 139 |
+
They use the key to decrypt the data.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:51,000 --> 00:01:53,000
|
| 143 |
+
This is going to work different.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:53,000 --> 00:01:58,000
|
| 147 |
+
And for that I want to I want to draw a little diagram here to get you guys an understanding of the
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:01:58,000 --> 00:02:00,000
|
| 151 |
+
encryption and decryption process.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:02,000 --> 00:02:05,000
|
| 155 |
+
So let's go in here and let me just draw.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:05,000 --> 00:02:07,000
|
| 159 |
+
Let's say you have two users on a network.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:07,000 --> 00:02:11,000
|
| 163 |
+
There's Andrew and there's Mary.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:11,000 --> 00:02:18,000
|
| 167 |
+
Now the way the encryption process works here is that I'm going to have a public private Mary also has
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:18,000 --> 00:02:20,000
|
| 171 |
+
a public private key.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:20,000 --> 00:02:24,000
|
| 175 |
+
But let's say I want to transfer data to Mary.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:24,000 --> 00:02:26,000
|
| 179 |
+
I want to give Mary the answers to the exam.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:26,000 --> 00:02:27,000
|
| 183 |
+
So.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:28,000 --> 00:02:29,000
|
| 187 |
+
How am I going to do it?
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:29,000 --> 00:02:31,000
|
| 191 |
+
Well, I have data.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:32,000 --> 00:02:34,000
|
| 195 |
+
That I want to transfer to Mary.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:34,000 --> 00:02:38,000
|
| 199 |
+
What I'm going to do and says, hey, Mary, you you're free.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:38,000 --> 00:02:41,000
|
| 203 |
+
Okay, Mary, can you send me your public key?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:41,000 --> 00:02:45,000
|
| 207 |
+
Mary sends me her public key, and I encrypt the data with the public key.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:45,000 --> 00:02:47,000
|
| 211 |
+
And now I got cipher text.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:47,000 --> 00:02:50,000
|
| 215 |
+
I send it to Mary, a cipher text.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:50,000 --> 00:02:57,000
|
| 219 |
+
Mary then utilizes her private key to decrypt this data to get the plain text or the data.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:02:58,000 --> 00:02:59,000
|
| 223 |
+
So.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:01,000 --> 00:03:02,000
|
| 227 |
+
I put some lines here.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:02,000 --> 00:03:07,000
|
| 231 |
+
So that's the decryption process encryption and decryption process.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:07,000 --> 00:03:12,000
|
| 235 |
+
Now technically it doesn't actually work like this because we don't actually do this.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:13,000 --> 00:03:15,000
|
| 239 |
+
Uh, we use it in a hybrid method, but I'm going to cover that later.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:15,000 --> 00:03:17,000
|
| 243 |
+
But for now, just this is good enough.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:18,000 --> 00:03:20,000
|
| 247 |
+
Now I want to point out a couple of things here.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:20,000 --> 00:03:23,000
|
| 251 |
+
You notice that I never utilized any of my keys.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:24,000 --> 00:03:26,000
|
| 255 |
+
I utilize the person that was receiving the data keys.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:26,000 --> 00:03:28,000
|
| 259 |
+
I utilize their public key, right?
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:28,000 --> 00:03:29,000
|
| 263 |
+
Did you see that?
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:29,000 --> 00:03:30,000
|
| 267 |
+
Think about going to Amazon.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:30,000 --> 00:03:33,000
|
| 271 |
+
When you go to Amazon, you don't have any keys, but Amazon does.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:34,000 --> 00:03:36,000
|
| 275 |
+
Keep this in mind when I get to SSL.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:36,000 --> 00:03:41,000
|
| 279 |
+
So this is a really important system because there's a couple of things here I want to point out.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:41,000 --> 00:03:46,000
|
| 283 |
+
Notice the public key encrypted the data and a private key decrypted data.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:46,000 --> 00:03:47,000
|
| 287 |
+
That's a concept you need to understand.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:03:48,000 --> 00:03:52,000
|
| 291 |
+
So when one key encrypts, only the other key can decrypt it.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:03:52,000 --> 00:03:56,000
|
| 295 |
+
So when a public key encrypts, only the corresponding private key can decrypt it.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:03:56,000 --> 00:03:59,000
|
| 299 |
+
If the private key encrypts it and it does encrypt.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:03:59,000 --> 00:04:03,000
|
| 303 |
+
For those of you that say no in a digital signature, a private key does decrypt.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:03,000 --> 00:04:03,000
|
| 307 |
+
I'm sorry.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:03,000 --> 00:04:04,000
|
| 311 |
+
Encrypt.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:05,000 --> 00:04:07,000
|
| 315 |
+
If the private encrypt the public decrypts.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:07,000 --> 00:04:13,000
|
| 319 |
+
Remember that when one key encrypts, only the corresponding other key can decrypt it.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:13,000 --> 00:04:17,000
|
| 323 |
+
The public key cannot encrypt and decrypt at the same time.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:17,000 --> 00:04:20,000
|
| 327 |
+
The private key cannot encrypt and decrypt at the same time.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:20,000 --> 00:04:23,000
|
| 331 |
+
When one encrypts the other, one must decrypt.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:23,000 --> 00:04:24,000
|
| 335 |
+
And that's what you see here.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:24,000 --> 00:04:26,000
|
| 339 |
+
We take the data.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:26,000 --> 00:04:29,000
|
| 343 |
+
We encrypt it with Mary's public key.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:30,000 --> 00:04:34,000
|
| 347 |
+
She gets the ciphertext and she decrypts it with her private key to get the data.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:34,000 --> 00:04:38,000
|
| 351 |
+
So that's something that you must understand here.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:38,000 --> 00:04:38,000
|
| 355 |
+
Now.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:39,000 --> 00:04:42,000
|
| 359 |
+
That's the encryption process how it works.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:42,000 --> 00:04:47,000
|
| 363 |
+
But there are some advantages and disadvantages with this particular system.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:48,000 --> 00:04:51,000
|
| 367 |
+
First of all, its advantages.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:04:51,000 --> 00:04:53,000
|
| 371 |
+
Well, it solves a problem of key distribution.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:04:53,000 --> 00:04:55,000
|
| 375 |
+
You notice that we can all communicate.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:04:55,000 --> 00:04:59,000
|
| 379 |
+
There's no there's no need to share keys, right?
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:04:59,000 --> 00:05:05,000
|
| 383 |
+
If you remember, the problem with symmetric encryption was how do we get the key across the network
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:05,000 --> 00:05:07,000
|
| 387 |
+
and how do we get the key from this guy to this guy.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:07,000 --> 00:05:08,000
|
| 391 |
+
Well, this is not a problem anymore.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:08,000 --> 00:05:11,000
|
| 395 |
+
Now I just take somebody's public key and I encrypt it and give it to them.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:11,000 --> 00:05:18,000
|
| 399 |
+
Anyone that intercepts the connection between me and Mary can't decrypt it because they don't have Mary's
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:18,000 --> 00:05:18,000
|
| 403 |
+
private key.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:19,000 --> 00:05:22,000
|
| 407 |
+
So it solves the problem of distribution of the key.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:23,000 --> 00:05:25,000
|
| 411 |
+
You don't need to have a billion keys.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:25,000 --> 00:05:28,000
|
| 415 |
+
You don't need to have keys between people.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:28,000 --> 00:05:34,000
|
| 419 |
+
For example, all you need to do to find the number of keys and asymmetric that would be needed if you
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:34,000 --> 00:05:39,000
|
| 423 |
+
are using just pure asymmetric if you have two users, four keys, right?
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:39,000 --> 00:05:44,000
|
| 427 |
+
If you have eight people, each of them would just need two keys with 16 keys.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:44,000 --> 00:05:45,000
|
| 431 |
+
That's it.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:45,000 --> 00:05:46,000
|
| 435 |
+
This times it by two.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:05:46,000 --> 00:05:46,000
|
| 439 |
+
Easy enough.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:05:47,000 --> 00:05:52,000
|
| 443 |
+
So the key distribution, the key management is pretty easy.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:05:53,000 --> 00:05:59,000
|
| 447 |
+
It provides a method for digital signature which is important for authentication and repudiation.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:05:59,000 --> 00:06:03,000
|
| 451 |
+
It has the ability to do non-repudiation authentication.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:03,000 --> 00:06:09,000
|
| 455 |
+
And the reason is because there is something unique to you.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:10,000 --> 00:06:13,000
|
| 459 |
+
There's something unique to you which is your private key.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:14,000 --> 00:06:16,000
|
| 463 |
+
Let me give you guys an example of this.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:16,000 --> 00:06:18,000
|
| 467 |
+
Let's say there is Andrew.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:19,000 --> 00:06:20,000
|
| 471 |
+
Andrew has a memo.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:22,000 --> 00:06:22,000
|
| 475 |
+
That's me.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:22,000 --> 00:06:26,000
|
| 479 |
+
I have a memo that I want to give to everybody in the company.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:27,000 --> 00:06:32,000
|
| 483 |
+
If I encrypt now I have two keys, a public and a private key.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:32,000 --> 00:06:38,000
|
| 487 |
+
Remember, if my public key encrypts, only my private key decrypts, if my private encrypts, only
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:06:38,000 --> 00:06:47,000
|
| 491 |
+
my public decrypts, my private key is given to no one in the entire world but my private, and my private
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:06:47,000 --> 00:06:48,000
|
| 495 |
+
key is given to no one in the world.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:06:48,000 --> 00:06:50,000
|
| 499 |
+
But my public key is given to everyone in the world.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:06:51,000 --> 00:06:59,000
|
| 503 |
+
What I could do is this I could encrypt this memo with my private key to get ciphertext.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:00,000 --> 00:07:01,000
|
| 507 |
+
Okay.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:01,000 --> 00:07:04,000
|
| 511 |
+
And then I could give this out to everybody in the business.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:04,000 --> 00:07:06,000
|
| 515 |
+
Who can decrypt this memo?
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:07,000 --> 00:07:08,000
|
| 519 |
+
Everyone.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:08,000 --> 00:07:09,000
|
| 523 |
+
Why?
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:09,000 --> 00:07:13,000
|
| 527 |
+
Because it was encrypted with the private key, not the public key.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:13,000 --> 00:07:14,000
|
| 531 |
+
The public key.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:14,000 --> 00:07:16,000
|
| 535 |
+
Everybody has my public key.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:16,000 --> 00:07:17,000
|
| 539 |
+
Hence the name public.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:17,000 --> 00:07:19,000
|
| 543 |
+
Well, why would I do that?
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:07:19,000 --> 00:07:21,000
|
| 547 |
+
Why would I encrypt something so the world can decrypt?
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:07:21,000 --> 00:07:23,000
|
| 551 |
+
It kind of defeats the purpose.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:07:23,000 --> 00:07:26,000
|
| 555 |
+
No, the purpose is non-repudiation.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:07:26,000 --> 00:07:29,000
|
| 559 |
+
The purpose is you would be 100% sure.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:07:29,000 --> 00:07:32,000
|
| 563 |
+
And I cannot deny that that memo came from me.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:07:32,000 --> 00:07:36,000
|
| 567 |
+
If you use my private key to decrypt the data, I'm sorry.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:07:36,000 --> 00:07:42,000
|
| 571 |
+
My public key to decrypt the data, then, you know, it had to be encrypted with something only I have,
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:07:42,000 --> 00:07:44,000
|
| 575 |
+
which is my private key.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:07:45,000 --> 00:07:51,000
|
| 579 |
+
So this forms the basis of a digital signature, which we'll talk about later in the course.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:07:51,000 --> 00:07:53,000
|
| 583 |
+
So it does that versus symmetric.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:07:53,000 --> 00:07:55,000
|
| 587 |
+
And you see symmetric encryption.
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:07:55,000 --> 00:07:56,000
|
| 591 |
+
Everybody was sharing a key.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:07:56,000 --> 00:07:58,000
|
| 595 |
+
There was nothing unique to someone.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:07:58,000 --> 00:08:01,000
|
| 599 |
+
Everybody had basically the same key.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:08:01,000 --> 00:08:03,000
|
| 603 |
+
Everybody needed the same key to encrypt and decrypt the data.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:08:03,000 --> 00:08:06,000
|
| 607 |
+
They were part of that communication.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:08:07,000 --> 00:08:08,000
|
| 611 |
+
Now.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:08:08,000 --> 00:08:09,000
|
| 615 |
+
It sounds good.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:08:09,000 --> 00:08:12,000
|
| 619 |
+
No key distribution problem, right?
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:08:12,000 --> 00:08:13,000
|
| 623 |
+
No problem distributing the key.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:08:13,000 --> 00:08:15,000
|
| 627 |
+
Okay, that's no problem doing that.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:08:15,000 --> 00:08:17,000
|
| 631 |
+
We don't need a billion keys.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:08:17,000 --> 00:08:18,000
|
| 635 |
+
We don't need a lot of keys.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:08:18,000 --> 00:08:23,000
|
| 639 |
+
If we don't, you know, we have a lot of users, so key management is easy.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:08:24,000 --> 00:08:28,000
|
| 643 |
+
Uh, we have this easy thing of doing digital signatures.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:08:29,000 --> 00:08:32,000
|
| 647 |
+
But why don't we use it to encrypt bulk data?
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:08:32,000 --> 00:08:37,000
|
| 651 |
+
In today's world, we actually don't use asymmetric encryption to encrypt larger data.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:08:37,000 --> 00:08:43,000
|
| 655 |
+
Now, basically any data for that matter, the actual private information per se, we don't actually
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:08:43,000 --> 00:08:49,000
|
| 659 |
+
use it to encrypt bulk data or large amounts of data because it is very slow.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:08:50,000 --> 00:08:56,000
|
| 663 |
+
You see, it's computationally intensive, much more than symmetric encryption, making it slower for
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:08:56,000 --> 00:08:57,000
|
| 667 |
+
large amounts of data.
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:08:57,000 --> 00:09:00,000
|
| 671 |
+
It requires also a careful management of those private keys.
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:09:01,000 --> 00:09:03,000
|
| 675 |
+
If your private key is compromised, you need a new pair.
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:09:03,000 --> 00:09:05,000
|
| 679 |
+
And it's because of.
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:09:06,000 --> 00:09:08,000
|
| 683 |
+
This point right here.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:09:08,000 --> 00:09:09,000
|
| 687 |
+
See that point right there?
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:09:09,000 --> 00:09:13,000
|
| 691 |
+
This computationally intensive?
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:09:14,000 --> 00:09:20,000
|
| 695 |
+
Uh, problem is really what doesn't make it replace symmetric.
|
| 696 |
+
|
| 697 |
+
175
|
| 698 |
+
00:09:20,000 --> 00:09:22,000
|
| 699 |
+
Somebody say is asymmetric going to replace symmetric.
|
| 700 |
+
|
| 701 |
+
176
|
| 702 |
+
00:09:22,000 --> 00:09:27,000
|
| 703 |
+
No it's not because it's you really can't use it for large blocks of data because it's too -- slow.
|
| 704 |
+
|
| 705 |
+
177
|
| 706 |
+
00:09:28,000 --> 00:09:31,000
|
| 707 |
+
So if you notice these two algorithms, they cancel each other out.
|
| 708 |
+
|
| 709 |
+
178
|
| 710 |
+
00:09:31,000 --> 00:09:33,000
|
| 711 |
+
So one is fast, one is slow.
|
| 712 |
+
|
| 713 |
+
179
|
| 714 |
+
00:09:33,000 --> 00:09:36,000
|
| 715 |
+
One has a problem with with distributing keys.
|
| 716 |
+
|
| 717 |
+
180
|
| 718 |
+
00:09:36,000 --> 00:09:40,000
|
| 719 |
+
One doesn't have this problem distributing keys one can't doesn't have something unique to the user.
|
| 720 |
+
|
| 721 |
+
181
|
| 722 |
+
00:09:40,000 --> 00:09:41,000
|
| 723 |
+
But this one does.
|
| 724 |
+
|
| 725 |
+
182
|
| 726 |
+
00:09:41,000 --> 00:09:46,000
|
| 727 |
+
It seems like all the bad is good here and all the bad, all the good is bad there.
|
| 728 |
+
|
| 729 |
+
183
|
| 730 |
+
00:09:47,000 --> 00:09:48,000
|
| 731 |
+
You get the point.
|
| 732 |
+
|
| 733 |
+
184
|
| 734 |
+
00:09:49,000 --> 00:09:50,000
|
| 735 |
+
So what do we do?
|
| 736 |
+
|
| 737 |
+
185
|
| 738 |
+
00:09:50,000 --> 00:09:52,000
|
| 739 |
+
Well, there's a way to combine them again.
|
| 740 |
+
|
| 741 |
+
186
|
| 742 |
+
00:09:52,000 --> 00:09:54,000
|
| 743 |
+
Hybrid cryptography is a video on that.
|
| 744 |
+
|
| 745 |
+
187
|
| 746 |
+
00:09:54,000 --> 00:09:55,000
|
| 747 |
+
Talk about that later.
|
| 748 |
+
|
| 749 |
+
188
|
| 750 |
+
00:09:56,000 --> 00:09:57,000
|
| 751 |
+
Now.
|
| 752 |
+
|
| 753 |
+
189
|
| 754 |
+
00:09:57,000 --> 00:10:05,000
|
| 755 |
+
Because things like it has ability to be unique to people, because it has that digital signature and
|
| 756 |
+
|
| 757 |
+
190
|
| 758 |
+
00:10:05,000 --> 00:10:06,000
|
| 759 |
+
the safe distribution of keys.
|
| 760 |
+
|
| 761 |
+
191
|
| 762 |
+
00:10:06,000 --> 00:10:10,000
|
| 763 |
+
It basically is a cornerstone for protecting all data on the internet today, because things like SSL
|
| 764 |
+
|
| 765 |
+
192
|
| 766 |
+
00:10:10,000 --> 00:10:11,000
|
| 767 |
+
can't work without it.
|
| 768 |
+
|
| 769 |
+
193
|
| 770 |
+
00:10:12,000 --> 00:10:14,000
|
| 771 |
+
So keep that in mind for now.
|
| 772 |
+
|
| 773 |
+
194
|
| 774 |
+
00:10:14,000 --> 00:10:18,000
|
| 775 |
+
I need you guys to understand what a what asymmetric is.
|
| 776 |
+
|
| 777 |
+
195
|
| 778 |
+
00:10:18,000 --> 00:10:19,000
|
| 779 |
+
Quick recap as we end this.
|
| 780 |
+
|
| 781 |
+
196
|
| 782 |
+
00:10:20,000 --> 00:10:22,000
|
| 783 |
+
Asymmetric is based on the principle of two keys.
|
| 784 |
+
|
| 785 |
+
197
|
| 786 |
+
00:10:22,000 --> 00:10:27,000
|
| 787 |
+
Everybody in the asymmetric realm has two keys a public key and a private key.
|
| 788 |
+
|
| 789 |
+
198
|
| 790 |
+
00:10:27,000 --> 00:10:31,000
|
| 791 |
+
The public key to give out to anyone the private key they keep only to themselves.
|
| 792 |
+
|
| 793 |
+
199
|
| 794 |
+
00:10:31,000 --> 00:10:36,000
|
| 795 |
+
When one key encrypts, only the other one can decrypt, they both encrypt and decrypt.
|
| 796 |
+
|
| 797 |
+
200
|
| 798 |
+
00:10:36,000 --> 00:10:36,000
|
| 799 |
+
So now.
|
| 800 |
+
|
| 801 |
+
201
|
| 802 |
+
00:10:38,000 --> 00:10:39,000
|
| 803 |
+
Pros and cons.
|
| 804 |
+
|
| 805 |
+
202
|
| 806 |
+
00:10:39,000 --> 00:10:45,000
|
| 807 |
+
The good thing is that it's easy to distribute keys because if the keys the secrets are not shared,
|
| 808 |
+
|
| 809 |
+
203
|
| 810 |
+
00:10:45,000 --> 00:10:47,000
|
| 811 |
+
you can give your public key to anyone.
|
| 812 |
+
|
| 813 |
+
204
|
| 814 |
+
00:10:47,000 --> 00:10:50,000
|
| 815 |
+
But if they encrypt, only your private key can can decrypt it.
|
| 816 |
+
|
| 817 |
+
205
|
| 818 |
+
00:10:51,000 --> 00:10:57,000
|
| 819 |
+
This is good because if there's something unique to your private key now, you can use it for non-repudiation,
|
| 820 |
+
|
| 821 |
+
206
|
| 822 |
+
00:10:57,000 --> 00:10:58,000
|
| 823 |
+
like with digital signatures.
|
| 824 |
+
|
| 825 |
+
207
|
| 826 |
+
00:10:59,000 --> 00:11:00,000
|
| 827 |
+
But what's bad about it?
|
| 828 |
+
|
| 829 |
+
208
|
| 830 |
+
00:11:00,000 --> 00:11:02,000
|
| 831 |
+
Well, it's too slow.
|
| 832 |
+
|
| 833 |
+
209
|
| 834 |
+
00:11:02,000 --> 00:11:06,000
|
| 835 |
+
It's very, very computationally intensive.
|
| 836 |
+
|
| 837 |
+
210
|
| 838 |
+
00:11:06,000 --> 00:11:09,000
|
| 839 |
+
And for those reasons you cannot use it to encrypt bulk data.
|
| 840 |
+
|
| 841 |
+
211
|
| 842 |
+
00:11:09,000 --> 00:11:14,000
|
| 843 |
+
So that way we have to find a way to encrypt bulk data, which we'll talk about coming up later in hybrid
|
| 844 |
+
|
| 845 |
+
212
|
| 846 |
+
00:11:14,000 --> 00:11:15,000
|
| 847 |
+
cryptography.
|
| 848 |
+
|
| 849 |
+
213
|
| 850 |
+
00:11:15,000 --> 00:11:19,000
|
| 851 |
+
But before we do that, let's take a look at some of the asymmetric algorithms.
|
| 852 |
+
|
07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,268 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
Okay, let's take a look at different asymmetric algorithms that you need to know or at least understand
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:07,000
|
| 7 |
+
for your exam.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:07,000 --> 00:00:13,000
|
| 11 |
+
Now, you don't need to know the math behind them or how it works, but you do need to know what they
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:13,000 --> 00:00:15,000
|
| 15 |
+
are and maybe some pros and cons about them.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:15,000 --> 00:00:19,000
|
| 19 |
+
So let's go ahead and get started on this now.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:20,000 --> 00:00:27,000
|
| 23 |
+
The world's most famous asymmetric algorithm is RSA d most famous algorithm out there.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:27,000 --> 00:00:34,000
|
| 27 |
+
I would say 80% of communications that utilizes certificates is basically going to run on RSA.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:34,000 --> 00:00:43,000
|
| 31 |
+
Now, RSA is based on the difficulty of factoring the product of two large prime numbers.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:43,000 --> 00:00:47,000
|
| 35 |
+
Now, I'm not going to get into the math, but that's something you probably might see on a question
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:47,000 --> 00:00:47,000
|
| 39 |
+
here and there.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:47,000 --> 00:00:52,000
|
| 43 |
+
It does use as large key sizes from 1024 to 4096.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:52,000 --> 00:00:57,000
|
| 47 |
+
Most of the RSA keys that I see is going to be 2048 bit.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:58,000 --> 00:01:04,000
|
| 51 |
+
This is widely used in things like digital signatures, key exchanges and of course SSL, TLS.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:01:05,000 --> 00:01:10,000
|
| 55 |
+
The other one is elliptic curve cryptography, now elliptic curve.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:10,000 --> 00:01:13,000
|
| 59 |
+
This is based on a different form of math.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:13,000 --> 00:01:18,000
|
| 63 |
+
The elliptic curves over a specific field a finite field.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:18,000 --> 00:01:24,000
|
| 67 |
+
It offers a higher degree of security with a smaller key size compared to RSA now because it's a different
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:24,000 --> 00:01:25,000
|
| 71 |
+
form of math.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:26,000 --> 00:01:32,000
|
| 75 |
+
It has the advantage of being very secure with a small key versus RSA.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:32,000 --> 00:01:34,000
|
| 79 |
+
For it to be secure, it needs a big key.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:34,000 --> 00:01:39,000
|
| 83 |
+
For example, like I said, most of the RSA keys ECC is 2048 bit.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:41,000 --> 00:01:50,000
|
| 87 |
+
Notice that this one here, it says here that 256 bit key in ECC is considered as secure as a 3072 bit.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:50,000 --> 00:01:52,000
|
| 91 |
+
So that's a giant thing if you think about it.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:52,000 --> 00:01:57,000
|
| 95 |
+
256 bit is has the same security as 3072.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:57,000 --> 00:01:58,000
|
| 99 |
+
Now if you're thinking, well, why does that matter so much?
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:58,000 --> 00:02:07,000
|
| 103 |
+
Because the bigger the key, the more CPU you need, the more memory you need to store that key.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:02:07,000 --> 00:02:10,000
|
| 107 |
+
Now if you're thinking, well, it's only bits, it's not that much, right?
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:02:10,000 --> 00:02:19,000
|
| 111 |
+
If you get four gigs of if you have four gigabyte of memory, that's 32 billion bits of memory in your
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:02:19,000 --> 00:02:19,000
|
| 115 |
+
computer.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:19,000 --> 00:02:20,000
|
| 119 |
+
And this is only four.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:20,000 --> 00:02:21,000
|
| 123 |
+
But remember, if you're a server.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:22,000 --> 00:02:28,000
|
| 127 |
+
And you have thousands or millions of connections, and you're managing all the keys for all these connections,
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:28,000 --> 00:02:30,000
|
| 131 |
+
which is going to get bogged down pretty quickly.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:30,000 --> 00:02:31,000
|
| 135 |
+
All right.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:31,000 --> 00:02:32,000
|
| 139 |
+
Did you know four gigs is 32 billion?
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:32,000 --> 00:02:33,000
|
| 143 |
+
Did you know that?
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:34,000 --> 00:02:36,000
|
| 147 |
+
Four gigabyte is 32 billion bits.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:37,000 --> 00:02:39,000
|
| 151 |
+
If you don't know, you better study some A-plus.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:39,000 --> 00:02:41,000
|
| 155 |
+
Learn your conversion.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:41,000 --> 00:02:44,000
|
| 159 |
+
Uh, so EC is getting more popular.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:44,000 --> 00:02:50,000
|
| 163 |
+
I want to mention it was taught that EC was going to replace RSA at some point due to its efficiency.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:50,000 --> 00:02:54,000
|
| 167 |
+
I haven't really seen that yet, but supposedly EC is replace it.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:54,000 --> 00:02:54,000
|
| 171 |
+
Why?
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:54,000 --> 00:02:58,000
|
| 175 |
+
It's going to give you more security, smaller key size and it basically does everything.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:58,000 --> 00:02:59,000
|
| 179 |
+
RSA.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:03:00,000 --> 00:03:01,000
|
| 183 |
+
Thus.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:03:01,000 --> 00:03:06,000
|
| 187 |
+
Now the other two are also famous, just not as famous as those two.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:06,000 --> 00:03:09,000
|
| 191 |
+
Diffie-Hellman was the first.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:10,000 --> 00:03:10,000
|
| 195 |
+
The first.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:10,000 --> 00:03:15,000
|
| 199 |
+
I'm pretty sure the first is, uh, asymmetric algorithm out there.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:15,000 --> 00:03:17,000
|
| 203 |
+
It was created by two guys, Diffie and Hellman.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:18,000 --> 00:03:23,000
|
| 207 |
+
Uh, this here was created for the passing of secret keys or symmetric keys.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:23,000 --> 00:03:24,000
|
| 211 |
+
That was its objectives.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:24,000 --> 00:03:29,000
|
| 215 |
+
It wasn't really meant to encrypt data or do any of the other things like RSA and ECC does.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:31,000 --> 00:03:35,000
|
| 219 |
+
Uh, it's most used again is to pass the secret keys that was out there.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:35,000 --> 00:03:37,000
|
| 223 |
+
The other one was Elgamal.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:38,000 --> 00:03:45,000
|
| 227 |
+
And this here was basically based on Diffie-Hellman, uh, and it provides a basis of other algorithms.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:45,000 --> 00:03:47,000
|
| 231 |
+
And this is really where this one was.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:47,000 --> 00:03:50,000
|
| 235 |
+
So the most used is going to be RSA.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:51,000 --> 00:03:54,000
|
| 239 |
+
ECC and Diffie-Hellman.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:54,000 --> 00:03:58,000
|
| 243 |
+
Out there, there's going to be the most used one for your exam.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:58,000 --> 00:04:05,000
|
| 247 |
+
I really don't need you guys to memorize all the bit, strings and or key sizes out there for these
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:04:05,000 --> 00:04:11,000
|
| 251 |
+
algorithms, but I do need you guys to know this is a symmetric this is an asymmetric algorithm.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:04:11,000 --> 00:04:12,000
|
| 255 |
+
Here are the pros.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:12,000 --> 00:04:15,000
|
| 259 |
+
And here is the cons of using symmetric and asymmetric.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:15,000 --> 00:04:17,000
|
| 263 |
+
That's generally what your exam asks.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:17,000 --> 00:04:19,000
|
| 267 |
+
So make sure you note them for your tests.
|
| 268 |
+
|
07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,488 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
In this video, I'm going to teach you how to combine asymmetric and symmetric to form the perfect cryptosystem.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:09,000
|
| 7 |
+
This is called hybrid cryptography.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:09,000 --> 00:00:12,000
|
| 11 |
+
And before I get into it, I want to point out something.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:12,000 --> 00:00:14,000
|
| 15 |
+
A lot of security guys don't know this.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:14,000 --> 00:00:20,000
|
| 19 |
+
A lot of people read books and different watch different videos about symmetric and asymmetric and things
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:20,000 --> 00:00:24,000
|
| 23 |
+
there and think that, for example, asymmetric is implemented by itself.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:24,000 --> 00:00:25,000
|
| 27 |
+
It's not.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:25,000 --> 00:00:26,000
|
| 31 |
+
Let me show you guys something.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:26,000 --> 00:00:28,000
|
| 35 |
+
So here is the Wikipedia article on hybrid cryptography.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:28,000 --> 00:00:30,000
|
| 39 |
+
I know, I know what you're gonna say, okay.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:30,000 --> 00:00:33,000
|
| 43 |
+
You know, it's not the best system out there, but it's it's good enough.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:34,000 --> 00:00:35,000
|
| 47 |
+
Hybrid cryptosystem.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:36,000 --> 00:00:37,000
|
| 51 |
+
I'm just going to go down here.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:37,000 --> 00:00:38,000
|
| 55 |
+
I want to read this part here for you.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:38,000 --> 00:00:46,000
|
| 59 |
+
Notice it says all practical implementations of public key cryptography today employ the use of a hybrid
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:46,000 --> 00:00:47,000
|
| 63 |
+
system.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:48,000 --> 00:00:50,000
|
| 67 |
+
All okay.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:50,000 --> 00:00:56,000
|
| 71 |
+
Basically any time we use asymmetric encryption it's never basically used by itself.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:56,000 --> 00:01:03,000
|
| 75 |
+
All implementations of it that we use in the real world, and not just the theoretical world is based
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:03,000 --> 00:01:05,000
|
| 79 |
+
on a hybrid cryptosystem.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:05,000 --> 00:01:09,000
|
| 83 |
+
And in this video I want you guys to learn what that is like.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:09,000 --> 00:01:11,000
|
| 87 |
+
What exactly is a hybrid cryptosystem.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:11,000 --> 00:01:14,000
|
| 91 |
+
And I want to draw you guys a quick diagram how it's done.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:15,000 --> 00:01:16,000
|
| 95 |
+
So let's get let's get into this.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:16,000 --> 00:01:19,000
|
| 99 |
+
So what exactly is a hybrid cryptosystem.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:19,000 --> 00:01:24,000
|
| 103 |
+
Well as you can imagine it takes the it takes the good of symmetric.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:24,000 --> 00:01:27,000
|
| 107 |
+
The good of asymmetric combines them.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:27,000 --> 00:01:29,000
|
| 111 |
+
Remember one there basically were like opposites.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:29,000 --> 00:01:31,000
|
| 115 |
+
What's good here is bad here.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:31,000 --> 00:01:31,000
|
| 119 |
+
What's bad here.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:31,000 --> 00:01:32,000
|
| 123 |
+
What's good here.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:32,000 --> 00:01:34,000
|
| 127 |
+
So if we combine them we get the perfect system.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:34,000 --> 00:01:35,000
|
| 131 |
+
That's really what it is.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:36,000 --> 00:01:43,000
|
| 135 |
+
Basically, when we combine them, we're going to use the asymmetric algorithms for the secure key exchange.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:43,000 --> 00:01:47,000
|
| 139 |
+
And then we're going to use the symmetric for encrypting the actual data.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:47,000 --> 00:01:52,000
|
| 143 |
+
Remember something symmetric is good at encrypting bulk data.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:52,000 --> 00:01:53,000
|
| 147 |
+
Asymmetric is not.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:01:53,000 --> 00:01:56,000
|
| 151 |
+
But asymmetric doesn't have a problem of key exchange.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:01:56,000 --> 00:01:59,000
|
| 155 |
+
Now if asymmetric has to encrypt.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:00,000 --> 00:02:01,000
|
| 159 |
+
Just a symmetric key.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:01,000 --> 00:02:04,000
|
| 163 |
+
It's cool because a symmetric key is pretty small.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:04,000 --> 00:02:07,000
|
| 167 |
+
It's only 256 bits or 128 bit.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:07,000 --> 00:02:12,000
|
| 171 |
+
It's not the size of a picture, which could be four megabytes, which would be 32 billion bits.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:12,000 --> 00:02:18,000
|
| 175 |
+
So remember this in the process that I'm about to cover now, I'm going to cover this exact process.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:18,000 --> 00:02:21,000
|
| 179 |
+
The text is listed here right now.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:21,000 --> 00:02:24,000
|
| 183 |
+
So I want to show you the hybrid cryptography system.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:24,000 --> 00:02:28,000
|
| 187 |
+
Now let's say there is Andy.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:29,000 --> 00:02:31,000
|
| 191 |
+
And there's Mary.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:31,000 --> 00:02:35,000
|
| 195 |
+
So we have Mary M-a-r-y and Andy.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:35,000 --> 00:02:38,000
|
| 199 |
+
So I have a public private key.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:38,000 --> 00:02:39,000
|
| 203 |
+
Public.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:39,000 --> 00:02:40,000
|
| 207 |
+
Private key.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:41,000 --> 00:02:44,000
|
| 211 |
+
Now, reality is, I don't really need keys here.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:44,000 --> 00:02:47,000
|
| 215 |
+
I'm just putting it there because everybody technically the system has it.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:47,000 --> 00:02:51,000
|
| 219 |
+
But remember, if you're on the internet and you're using things that you don't have any public private
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:02:51,000 --> 00:02:52,000
|
| 223 |
+
keys in your machine.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:02:53,000 --> 00:02:54,000
|
| 227 |
+
Now here's how it works.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:02:54,000 --> 00:03:00,000
|
| 231 |
+
So let's say I have data that I want to transfer to Mary.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:01,000 --> 00:03:04,000
|
| 235 |
+
Here's what I'm going to do on my computer.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:04,000 --> 00:03:07,000
|
| 239 |
+
I am going to generate a symmetric key.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:07,000 --> 00:03:11,000
|
| 243 |
+
This symmetric key is known as a session key.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:11,000 --> 00:03:15,000
|
| 247 |
+
The session key is a symmetric key like an AES session key.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:16,000 --> 00:03:22,000
|
| 251 |
+
What I'm going to do is I'm going to encrypt this data with this to form ciphertext.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:24,000 --> 00:03:25,000
|
| 255 |
+
Okay.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:25,000 --> 00:03:32,000
|
| 259 |
+
So ciphertext is the data is encrypted with the symmetric key to form ciphertext.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:32,000 --> 00:03:36,000
|
| 263 |
+
What I'm going to do is I'm going to then say hey Mary, send me your public key.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:36,000 --> 00:03:39,000
|
| 267 |
+
Mary sends me her public key, but I'm not going to encrypt the data with it.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:39,000 --> 00:03:41,000
|
| 271 |
+
The data has already been encrypted.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:41,000 --> 00:03:44,000
|
| 275 |
+
What am I going to encrypt the symmetric key if you said that.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:44,000 --> 00:03:44,000
|
| 279 |
+
Correct.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:44,000 --> 00:03:46,000
|
| 283 |
+
So I have ciphertext data.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:47,000 --> 00:03:51,000
|
| 287 |
+
And now I have ciphertext symmetric key.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:03:52,000 --> 00:03:54,000
|
| 291 |
+
What I do is now I send this to Mary.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:03:54,000 --> 00:04:03,000
|
| 295 |
+
Mary receives the ciphertext symmetric key and she receives ciphertext data.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:03,000 --> 00:04:04,000
|
| 299 |
+
You guys see that?
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:04,000 --> 00:04:04,000
|
| 303 |
+
Yep.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:05,000 --> 00:04:07,000
|
| 307 |
+
How does Mary get the data?
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:07,000 --> 00:04:14,000
|
| 311 |
+
Well, now Mary utilizes her private key to decrypt the symmetric key.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:14,000 --> 00:04:18,000
|
| 315 |
+
Remember, the symmetric key was encrypted with her public, so it could only be decrypted with her
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:18,000 --> 00:04:19,000
|
| 319 |
+
private.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:19,000 --> 00:04:23,000
|
| 323 |
+
And now Mary has the symmetric key.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:23,000 --> 00:04:26,000
|
| 327 |
+
She then uses that symmetric key to decrypt the data.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:26,000 --> 00:04:27,000
|
| 331 |
+
Now she has the pure data.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:28,000 --> 00:04:32,000
|
| 335 |
+
So that is the process of asymmetric.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:32,000 --> 00:04:34,000
|
| 339 |
+
So let's sorry hybrid cryptography.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:34,000 --> 00:04:36,000
|
| 343 |
+
Let's do a quick quick review.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:37,000 --> 00:04:37,000
|
| 347 |
+
Okay.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:37,000 --> 00:04:39,000
|
| 351 |
+
So remember I don't need keys.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:39,000 --> 00:04:40,000
|
| 355 |
+
So what do I do.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:40,000 --> 00:04:44,000
|
| 359 |
+
I have the data I generate a symmetric key on this machine.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:44,000 --> 00:04:50,000
|
| 363 |
+
I then encrypt that symmetric key uh with Mary's public key.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:50,000 --> 00:04:52,000
|
| 367 |
+
See that I took it I gave it to her.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:04:52,000 --> 00:04:56,000
|
| 371 |
+
She gave it to me, I encrypt it, and now I have ciphertext data.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:04:57,000 --> 00:05:01,000
|
| 375 |
+
Uh, I have the ciphertext data, and I have ciphertext symmetric key and send it to her.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:01,000 --> 00:05:03,000
|
| 379 |
+
Now I want you to watch this connection.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:03,000 --> 00:05:08,000
|
| 383 |
+
If there's a hacker right here, the hacker is seeing ciphertext data and ciphertext symmetric key.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:08,000 --> 00:05:10,000
|
| 387 |
+
Everything you basically see is ciphertext.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:10,000 --> 00:05:12,000
|
| 391 |
+
He never sees plaintext.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:12,000 --> 00:05:16,000
|
| 395 |
+
When she receives it, she uses her private key to decrypt the symmetric key.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:17,000 --> 00:05:21,000
|
| 399 |
+
And then uses that symmetric key to decrypt the ciphertext data to get the data.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:21,000 --> 00:05:30,000
|
| 403 |
+
So I got data from me to her using a combination of of symmetric and asymmetric keys.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:30,000 --> 00:05:33,000
|
| 407 |
+
This is the most efficient way of doing this.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:35,000 --> 00:05:40,000
|
| 411 |
+
Now hybrid cryptography system combines this.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:40,000 --> 00:05:43,000
|
| 415 |
+
All right combines the efficiency of symmetric key.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:43,000 --> 00:05:44,000
|
| 419 |
+
So we get notice the data.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:44,000 --> 00:05:47,000
|
| 423 |
+
The bulk data was using the symmetric.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:47,000 --> 00:05:55,000
|
| 427 |
+
And of course that incredible key exchange process or easy management of the keys in asymmetric was
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:55,000 --> 00:05:55,000
|
| 431 |
+
use.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:56,000 --> 00:06:01,000
|
| 435 |
+
One of the great things is that even if a symmetric key is compromised, it only affects one session
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:01,000 --> 00:06:03,000
|
| 439 |
+
every time I encrypt data.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:03,000 --> 00:06:05,000
|
| 443 |
+
Every session I make a brand new session key.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:06,000 --> 00:06:08,000
|
| 447 |
+
This is very scalable and used in numerous systems.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:08,000 --> 00:06:17,000
|
| 451 |
+
In fact, all implementations of things like SSL, all web connections nowadays is basically that what
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:17,000 --> 00:06:21,000
|
| 455 |
+
I showed you there, that diagram I wrote are just basically just draw it for you, as is the basis
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:21,000 --> 00:06:23,000
|
| 459 |
+
of the SSL handshake.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:23,000 --> 00:06:29,000
|
| 463 |
+
There's more to it, but that's basically the basis of how the whole SSL handshake works.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:30,000 --> 00:06:32,000
|
| 467 |
+
So all types of converters, email, VPNs and so on.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:32,000 --> 00:06:40,000
|
| 471 |
+
Anywhere that we have a symmetric anywhere that is symmetric uses asymmetric encryption, we'll have
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:40,000 --> 00:06:42,000
|
| 475 |
+
hybrid cryptography okay.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:42,000 --> 00:06:47,000
|
| 479 |
+
So you may want to watch that process again understand the pros and cons of it and the process.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:47,000 --> 00:06:53,000
|
| 483 |
+
Don't worry too much about the algorithm, but just remember all practical implementations of asymmetric
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:53,000 --> 00:06:55,000
|
| 487 |
+
utilizes hybrid cryptography.
|
| 488 |
+
|
07 - Cryptography/011 Hashing OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,1600 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
In this video, we're going to get started in the beautiful world of cryptographic hashes.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:11,000
|
| 7 |
+
Now we covered asymmetric and symmetric asymmetric and a asymmetric and symmetric works directly on
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:11,000 --> 00:00:13,000
|
| 11 |
+
data and produces things like ciphertext.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:13,000 --> 00:00:15,000
|
| 15 |
+
In this one we're going to do something different.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:15,000 --> 00:00:20,000
|
| 19 |
+
What we're going to be doing is we're going to be taking data of any length and turn it into a fixed
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:20,000 --> 00:00:21,000
|
| 23 |
+
length hash.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:21,000 --> 00:00:24,000
|
| 27 |
+
This doesn't actually encrypt the data at all.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:26,000
|
| 31 |
+
This is just a cryptographic number.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:26,000 --> 00:00:31,000
|
| 35 |
+
It's basically a value that represents the data.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:31,000 --> 00:00:35,000
|
| 39 |
+
It's not used to replace the data and it's not used to be decrypted.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:35,000 --> 00:00:38,000
|
| 43 |
+
This is something that's best shown than me trying to explain it.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:38,000 --> 00:00:39,000
|
| 47 |
+
Let me show it to you.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:39,000 --> 00:00:42,000
|
| 51 |
+
And then we're going to get into the nitty gritty detail.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:42,000 --> 00:00:44,000
|
| 55 |
+
I'm going to be showing you a hash function.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:44,000 --> 00:00:49,000
|
| 59 |
+
The most used hash function on the planet basically is going to be Sha 256.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:49,000 --> 00:00:52,000
|
| 63 |
+
We're going to get more into this function later on in the in these lessons.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:52,000 --> 00:00:55,000
|
| 67 |
+
But let's take a look.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:55,000 --> 00:00:57,000
|
| 71 |
+
So here I am at uh, this website.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:57,000 --> 00:01:02,000
|
| 75 |
+
And this is going to be a live view of a cryptographic hash functions getting done.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:02,000 --> 00:01:05,000
|
| 79 |
+
Now the link to this website is in the slides.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:05,000 --> 00:01:06,000
|
| 83 |
+
So I want to show you guys something.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:07,000 --> 00:01:12,000
|
| 87 |
+
I'm going to be entering my text at the bottom and at the bottom, at the top and at the bottom you're
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:12,000 --> 00:01:15,000
|
| 91 |
+
going to get your cryptographic hash output.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:15,000 --> 00:01:15,000
|
| 95 |
+
Let's see.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:15,000 --> 00:01:25,000
|
| 99 |
+
So I'm going to say did you guys know I have many certifications.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:25,000 --> 00:01:32,000
|
| 103 |
+
Now I want you guys to watch something every single time I touch that keyboard.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:33,000 --> 00:01:35,000
|
| 107 |
+
The whole hash function chain.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:35,000 --> 00:01:38,000
|
| 111 |
+
You see this function, right.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:38,000 --> 00:01:41,000
|
| 115 |
+
This particular output, this string.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:42,000 --> 00:01:43,000
|
| 119 |
+
Represents this data.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:44,000 --> 00:01:51,000
|
| 123 |
+
If this data is modified in its slightest, this entire string will change.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:52,000 --> 00:01:55,000
|
| 127 |
+
For example, I want you guys to select on the screen.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:55,000 --> 00:01:56,000
|
| 131 |
+
We make this bigger so we can all see.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:58,000 --> 00:01:58,000
|
| 135 |
+
Okay.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:59,000 --> 00:02:00,000
|
| 139 |
+
Select any value here.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:00,000 --> 00:02:04,000
|
| 143 |
+
It doesn't matter what this any value, any one of these.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:04,000 --> 00:02:06,000
|
| 147 |
+
Maybe you got this one or maybe this eight here.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:06,000 --> 00:02:08,000
|
| 151 |
+
And I'm just going to click in the data.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:08,000 --> 00:02:09,000
|
| 155 |
+
And I'm just going to add a period.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:09,000 --> 00:02:10,000
|
| 159 |
+
That's it.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:10,000 --> 00:02:11,000
|
| 163 |
+
I'm just going to add a period.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:12,000 --> 00:02:13,000
|
| 167 |
+
Did it change.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:13,000 --> 00:02:14,000
|
| 171 |
+
More than likely it changed.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:14,000 --> 00:02:15,000
|
| 175 |
+
All right.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:15,000 --> 00:02:17,000
|
| 179 |
+
This whole thing basically changes.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:17,000 --> 00:02:19,000
|
| 183 |
+
Almost all those values will change.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:20,000 --> 00:02:20,000
|
| 187 |
+
Let me continue.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:20,000 --> 00:02:27,000
|
| 191 |
+
Notice that there's two main properties I need you guys to know every single time I type something.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:28,000 --> 00:02:29,000
|
| 195 |
+
Uh, watch it change.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:29,000 --> 00:02:31,000
|
| 199 |
+
But there's something else that's not changing.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:31,000 --> 00:02:33,000
|
| 203 |
+
Let's let me see if you detect it.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:33,000 --> 00:02:41,000
|
| 207 |
+
So I hope you will get more certs than I have.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:42,000 --> 00:02:43,000
|
| 211 |
+
Okay.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:43,000 --> 00:02:43,000
|
| 215 |
+
Nope.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:43,000 --> 00:02:44,000
|
| 219 |
+
I put an extra space.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:02:44,000 --> 00:02:45,000
|
| 223 |
+
Let me remove it.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:02:45,000 --> 00:02:51,000
|
| 227 |
+
Notice every single time I type the hash is changing.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:02:51,000 --> 00:02:53,000
|
| 231 |
+
But there's something not changing.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:02:53,000 --> 00:02:56,000
|
| 235 |
+
And what's not changing is the size of this.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:02:56,000 --> 00:02:58,000
|
| 239 |
+
This thing stays the same.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:02:58,000 --> 00:03:00,000
|
| 243 |
+
Doesn't matter how much text I put.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:00,000 --> 00:03:02,000
|
| 247 |
+
You see, if I copy this here.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:04,000 --> 00:03:06,000
|
| 251 |
+
I paste it into that box.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:06,000 --> 00:03:12,000
|
| 255 |
+
Once again, the hash changes, but the size of the hash is not changing.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:12,000 --> 00:03:16,000
|
| 259 |
+
No matter what I put in here, the hash size of the hash will not change.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:16,000 --> 00:03:22,000
|
| 263 |
+
See, if I go in here and I put and I keep doing, it doesn't matter how many times I copy paste it,
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:22,000 --> 00:03:23,000
|
| 267 |
+
it will not change.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:24,000 --> 00:03:26,000
|
| 271 |
+
This is a very unique characteristics of this hash.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:26,000 --> 00:03:32,000
|
| 275 |
+
You see this particular value represents all this data.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:33,000 --> 00:03:39,000
|
| 279 |
+
So if anybody manipulates this data in any which way and you have this hash value.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:39,000 --> 00:03:43,000
|
| 283 |
+
So let's say I send you the data all of this and I send you this hash.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:44,000 --> 00:03:45,000
|
| 287 |
+
Okay.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:03:45,000 --> 00:03:49,000
|
| 291 |
+
You'll be able to tell if anybody manipulated it, because if somebody manipulates this data, maybe
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:03:49,000 --> 00:03:52,000
|
| 295 |
+
they went in here after this morning, they put a space.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:03:52,000 --> 00:03:53,000
|
| 299 |
+
Then of course, the hash will change.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:03:53,000 --> 00:03:55,000
|
| 303 |
+
You would know somebody modified that somehow.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:03:56,000 --> 00:03:57,000
|
| 307 |
+
And that's what hashing is.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:03:57,000 --> 00:04:04,000
|
| 311 |
+
Hashing is about detecting modification of the data, the hash value, the string of characters that
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:04,000 --> 00:04:05,000
|
| 315 |
+
we saw.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:05,000 --> 00:04:07,000
|
| 319 |
+
That was a 256 bit hash.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:07,000 --> 00:04:10,000
|
| 323 |
+
What we saw here, this is 256 bit.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:10,000 --> 00:04:12,000
|
| 327 |
+
It's just written.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:13,000 --> 00:04:16,000
|
| 331 |
+
It's written in a different format than you would know in in binary.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:16,000 --> 00:04:17,000
|
| 335 |
+
Okay.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:17,000 --> 00:04:21,000
|
| 339 |
+
So in this particular one it's, uh, hexadecimal.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:21,000 --> 00:04:23,000
|
| 343 |
+
So it's 0298F.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:23,000 --> 00:04:26,000
|
| 347 |
+
Now it's a base 16.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:26,000 --> 00:04:28,000
|
| 351 |
+
So don't worry too much about the specific math.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:28,000 --> 00:04:29,000
|
| 355 |
+
Just know that this is 200.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:29,000 --> 00:04:31,000
|
| 359 |
+
This is 256 bit hash.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:31,000 --> 00:04:37,000
|
| 363 |
+
And any kind of changes in here will result in a change here.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:37,000 --> 00:04:40,000
|
| 367 |
+
Now let's talk about these characteristics of this.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:04:42,000 --> 00:04:45,000
|
| 371 |
+
Because there's a lot of things here we should be able to understand.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:04:45,000 --> 00:04:49,000
|
| 375 |
+
Number one is that when it comes to hashing what are we doing.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:04:49,000 --> 00:04:52,000
|
| 379 |
+
Well we're converting an input of any length.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:04:52,000 --> 00:04:54,000
|
| 383 |
+
Like I mentioned any length.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:04:54,000 --> 00:04:59,000
|
| 387 |
+
It could be something as small as one bit all the way to terabytes of data.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:04:59,000 --> 00:05:06,000
|
| 391 |
+
Doesn't matter into a fixed size string of text using a mathematical function.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:06,000 --> 00:05:07,000
|
| 395 |
+
That's the hash function.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:07,000 --> 00:05:08,000
|
| 399 |
+
That's what we just saw.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:09,000 --> 00:05:14,000
|
| 403 |
+
Now a hash function takes data input data, like a message produces that fixed length hash.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:14,000 --> 00:05:17,000
|
| 407 |
+
Now the thing to know is that it's you can't go back.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:17,000 --> 00:05:18,000
|
| 411 |
+
And we'll talk about that in a minute.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:20,000 --> 00:05:24,000
|
| 415 |
+
A good hash function produces a unique and distinct value for every single input.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:24,000 --> 00:05:27,000
|
| 419 |
+
Even a small change results in a significant one.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:27,000 --> 00:05:31,000
|
| 423 |
+
So that means that every time you type text in, you're going to get a different output.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:31,000 --> 00:05:34,000
|
| 427 |
+
Every time the text changes, the output changed.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:34,000 --> 00:05:35,000
|
| 431 |
+
Now we saw that.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:35,000 --> 00:05:39,000
|
| 435 |
+
Now, just in case you don't have your following, just the slides, I give you a few examples.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:05:39,000 --> 00:05:42,000
|
| 439 |
+
But you saw that here where that was this website I gave you.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:05:42,000 --> 00:05:43,000
|
| 443 |
+
This is a link I was at.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:05:43,000 --> 00:05:49,000
|
| 447 |
+
So you would just type in the value type in your text, the hash function, and then it would give you
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:05:49,000 --> 00:05:51,000
|
| 451 |
+
the different hashes.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:05:51,000 --> 00:05:54,000
|
| 455 |
+
Now this particular website has more than just Sha 256.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:05:54,000 --> 00:06:03,000
|
| 459 |
+
I think it has MD5 three shot 253 356 or I'm sorry 384 512 this is a variety of different ones there.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:03,000 --> 00:06:10,000
|
| 463 |
+
Now there are some things that I want to talk about in terms of hashing, right.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:10,000 --> 00:06:13,000
|
| 467 |
+
Some characteristics that we want to be familiar with.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:13,000 --> 00:06:16,000
|
| 471 |
+
Number one is that it's deterministic.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:16,000 --> 00:06:26,000
|
| 475 |
+
The same input always produces the same output every single time you hash that text.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:26,000 --> 00:06:31,000
|
| 479 |
+
It should always give you that exact exact output.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:31,000 --> 00:06:34,000
|
| 483 |
+
If the text is modified, the output is different.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:34,000 --> 00:06:41,000
|
| 487 |
+
And I want to show you guys, uh, I want to show you guys this, uh, in their.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:06:42,000 --> 00:06:43,000
|
| 491 |
+
So here's what I'm going to do.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:06:45,000 --> 00:06:47,000
|
| 495 |
+
I'm going to highlight all this and I'm going to.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:06:49,000 --> 00:06:51,000
|
| 499 |
+
Put I have.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:06:51,000 --> 00:06:53,000
|
| 503 |
+
I want to show you guys something because this is going to make more sense.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:06:53,000 --> 00:06:55,000
|
| 507 |
+
Have I have many certs.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:06:55,000 --> 00:06:55,000
|
| 511 |
+
All right.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:06:55,000 --> 00:06:56,000
|
| 515 |
+
This is my message.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:06:56,000 --> 00:07:02,000
|
| 519 |
+
Every time I do this, every time I type this text, it should give me this exact hash.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:02,000 --> 00:07:07,000
|
| 523 |
+
Doesn't matter where any time you run this text it should always give you this hash.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:07,000 --> 00:07:12,000
|
| 527 |
+
So let me just go here and I'm going to say Sha 256 online.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:13,000 --> 00:07:14,000
|
| 531 |
+
I'm just going to go to another website.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:15,000 --> 00:07:16,000
|
| 535 |
+
I'm just going to use theirs okay.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:16,000 --> 00:07:17,000
|
| 539 |
+
This is another website.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:17,000 --> 00:07:19,000
|
| 543 |
+
And let's drag this one here.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:07:19,000 --> 00:07:22,000
|
| 547 |
+
So we have two inputs on our screen.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:07:22,000 --> 00:07:27,000
|
| 551 |
+
So let's see if what I do here this this output should be matched in this one.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:07:27,000 --> 00:07:28,000
|
| 555 |
+
So let's see if we get it right.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:07:28,000 --> 00:07:32,000
|
| 559 |
+
So I'm going to take this I'm going to copy this I'm going to put it into this screen now.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:07:32,000 --> 00:07:34,000
|
| 563 |
+
So again it's the same function just a different site.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:07:35,000 --> 00:07:37,000
|
| 567 |
+
I'm just showing you that the output is going to match watch.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:07:37,000 --> 00:07:41,000
|
| 571 |
+
So I just put that there and let's see if the output matches.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:07:41,000 --> 00:07:43,000
|
| 575 |
+
Now I'm not going to go one by one here.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:07:43,000 --> 00:07:46,000
|
| 579 |
+
But the first couple should be fine e f.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:07:46,000 --> 00:07:48,000
|
| 583 |
+
Let's see this one.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:07:48,000 --> 00:07:52,000
|
| 587 |
+
Output F90F90 okay.
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:07:52,000 --> 00:07:55,000
|
| 591 |
+
What is it n with this one ends in 3266.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:07:55,000 --> 00:07:56,000
|
| 595 |
+
This one ends in three two, six, six.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:07:56,000 --> 00:07:56,000
|
| 599 |
+
See that?
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:07:57,000 --> 00:07:59,000
|
| 603 |
+
So if I go in here and I say I have.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:08:01,000 --> 00:08:04,000
|
| 607 |
+
66 shirts.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:08:04,000 --> 00:08:10,000
|
| 611 |
+
So if I go in here and I say same thing six.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:08:12,000 --> 00:08:15,000
|
| 615 |
+
66 certs should match.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:08:15,000 --> 00:08:16,000
|
| 619 |
+
Let's see again.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:08:16,000 --> 00:08:19,000
|
| 623 |
+
So look at this e f f.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:08:20,000 --> 00:08:21,000
|
| 627 |
+
E f f.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:08:21,000 --> 00:08:22,000
|
| 631 |
+
Okay, great.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:08:22,000 --> 00:08:23,000
|
| 635 |
+
This matches perfectly.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:08:23,000 --> 00:08:25,000
|
| 639 |
+
It ends in 0303.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:08:25,000 --> 00:08:26,000
|
| 643 |
+
So this one ends in 0303.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:08:27,000 --> 00:08:28,000
|
| 647 |
+
Exactly.
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:08:28,000 --> 00:08:34,000
|
| 651 |
+
So any time you type that text using that function, you should always get that output.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:08:34,000 --> 00:08:36,000
|
| 655 |
+
That's what that's the point I'm trying to make here.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:08:36,000 --> 00:08:43,000
|
| 659 |
+
Now that's important to understand because when we come to passwords, the world of password management
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:08:43,000 --> 00:08:46,000
|
| 663 |
+
you're going to need to know that, uh, okay.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:08:46,000 --> 00:08:48,000
|
| 667 |
+
So it's deterministic.
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:08:48,000 --> 00:08:49,000
|
| 671 |
+
It's fast.
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:08:49,000 --> 00:08:52,000
|
| 675 |
+
It should be able it doesn't really matter the size of it.
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:08:52,000 --> 00:08:55,000
|
| 679 |
+
It should be able to compute the hash relatively quickly.
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:08:56,000 --> 00:08:58,000
|
| 683 |
+
It should be preimage resistant.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:08:58,000 --> 00:09:01,000
|
| 687 |
+
Now this is something you have to understand.
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:09:01,000 --> 00:09:04,000
|
| 691 |
+
It is considered one way.
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:09:04,000 --> 00:09:07,000
|
| 695 |
+
What does that mean if I give you.
|
| 696 |
+
|
| 697 |
+
175
|
| 698 |
+
00:09:08,000 --> 00:09:16,000
|
| 699 |
+
A hash value, you should not be able to reconstruct the original input.
|
| 700 |
+
|
| 701 |
+
176
|
| 702 |
+
00:09:16,000 --> 00:09:19,000
|
| 703 |
+
Well, what does that mean?
|
| 704 |
+
|
| 705 |
+
177
|
| 706 |
+
00:09:19,000 --> 00:09:21,000
|
| 707 |
+
Well let's see.
|
| 708 |
+
|
| 709 |
+
178
|
| 710 |
+
00:09:21,000 --> 00:09:23,000
|
| 711 |
+
So if I give you.
|
| 712 |
+
|
| 713 |
+
179
|
| 714 |
+
00:09:25,000 --> 00:09:31,000
|
| 715 |
+
If I give you this value, there is no way you should be going back.
|
| 716 |
+
|
| 717 |
+
180
|
| 718 |
+
00:09:31,000 --> 00:09:32,000
|
| 719 |
+
It's one way.
|
| 720 |
+
|
| 721 |
+
181
|
| 722 |
+
00:09:32,000 --> 00:09:32,000
|
| 723 |
+
It's.
|
| 724 |
+
|
| 725 |
+
182
|
| 726 |
+
00:09:32,000 --> 00:09:35,000
|
| 727 |
+
Take the data, produce a cryptographic hash.
|
| 728 |
+
|
| 729 |
+
183
|
| 730 |
+
00:09:35,000 --> 00:09:42,000
|
| 731 |
+
You should never be able to turn this the cash value into the text itself.
|
| 732 |
+
|
| 733 |
+
184
|
| 734 |
+
00:09:43,000 --> 00:09:47,000
|
| 735 |
+
In fact, it's probably not even feasible because when you have large amounts of text, it's not feasible
|
| 736 |
+
|
| 737 |
+
185
|
| 738 |
+
00:09:48,000 --> 00:09:57,000
|
| 739 |
+
because you can have data that's 20MB, that's 160 bits being brought down to 256 bits.
|
| 740 |
+
|
| 741 |
+
186
|
| 742 |
+
00:09:58,000 --> 00:09:58,000
|
| 743 |
+
Okay.
|
| 744 |
+
|
| 745 |
+
187
|
| 746 |
+
00:09:58,000 --> 00:09:59,000
|
| 747 |
+
That's like me.
|
| 748 |
+
|
| 749 |
+
188
|
| 750 |
+
00:09:59,000 --> 00:10:03,000
|
| 751 |
+
You know, if you take a four megabyte file, that's 32 billion bits.
|
| 752 |
+
|
| 753 |
+
189
|
| 754 |
+
00:10:03,000 --> 00:10:08,000
|
| 755 |
+
That's like me giving you $256 and say, go make 4 billion, $32 million.
|
| 756 |
+
|
| 757 |
+
190
|
| 758 |
+
00:10:08,000 --> 00:10:10,000
|
| 759 |
+
Not very hard to do.
|
| 760 |
+
|
| 761 |
+
191
|
| 762 |
+
00:10:10,000 --> 00:10:15,000
|
| 763 |
+
So it is considered a one way function.
|
| 764 |
+
|
| 765 |
+
192
|
| 766 |
+
00:10:15,000 --> 00:10:15,000
|
| 767 |
+
Okay.
|
| 768 |
+
|
| 769 |
+
193
|
| 770 |
+
00:10:15,000 --> 00:10:17,000
|
| 771 |
+
What are some other function of this.
|
| 772 |
+
|
| 773 |
+
194
|
| 774 |
+
00:10:17,000 --> 00:10:18,000
|
| 775 |
+
Let's see.
|
| 776 |
+
|
| 777 |
+
195
|
| 778 |
+
00:10:19,000 --> 00:10:19,000
|
| 779 |
+
Okay.
|
| 780 |
+
|
| 781 |
+
196
|
| 782 |
+
00:10:19,000 --> 00:10:26,000
|
| 783 |
+
So the other thing here we have is going to be small changes leads to large differences.
|
| 784 |
+
|
| 785 |
+
197
|
| 786 |
+
00:10:26,000 --> 00:10:28,000
|
| 787 |
+
Now that means that we saw this earlier.
|
| 788 |
+
|
| 789 |
+
198
|
| 790 |
+
00:10:28,000 --> 00:10:32,000
|
| 791 |
+
You make one small change to to the text.
|
| 792 |
+
|
| 793 |
+
199
|
| 794 |
+
00:10:32,000 --> 00:10:36,000
|
| 795 |
+
Remember when I just added a space or just one letter change or put a period or something.
|
| 796 |
+
|
| 797 |
+
200
|
| 798 |
+
00:10:36,000 --> 00:10:38,000
|
| 799 |
+
The whole hash will change.
|
| 800 |
+
|
| 801 |
+
201
|
| 802 |
+
00:10:38,000 --> 00:10:40,000
|
| 803 |
+
This is called the avalanche effect.
|
| 804 |
+
|
| 805 |
+
202
|
| 806 |
+
00:10:40,000 --> 00:10:44,000
|
| 807 |
+
What that means is that basically it's like a cascading effect.
|
| 808 |
+
|
| 809 |
+
203
|
| 810 |
+
00:10:44,000 --> 00:10:46,000
|
| 811 |
+
Okay, you change it, then it changes the entire hash.
|
| 812 |
+
|
| 813 |
+
204
|
| 814 |
+
00:10:47,000 --> 00:10:51,000
|
| 815 |
+
Now, the one I want to spend a couple of minutes on is called collision resistance.
|
| 816 |
+
|
| 817 |
+
205
|
| 818 |
+
00:10:51,000 --> 00:10:53,000
|
| 819 |
+
What exactly is this?
|
| 820 |
+
|
| 821 |
+
206
|
| 822 |
+
00:10:53,000 --> 00:10:55,000
|
| 823 |
+
Well, you have to understand how this thing works.
|
| 824 |
+
|
| 825 |
+
207
|
| 826 |
+
00:10:55,000 --> 00:10:57,000
|
| 827 |
+
It basically takes data.
|
| 828 |
+
|
| 829 |
+
208
|
| 830 |
+
00:10:58,000 --> 00:11:01,000
|
| 831 |
+
Of any length and it produces this fixed length string of text.
|
| 832 |
+
|
| 833 |
+
209
|
| 834 |
+
00:11:01,000 --> 00:11:02,000
|
| 835 |
+
This hash.
|
| 836 |
+
|
| 837 |
+
210
|
| 838 |
+
00:11:03,000 --> 00:11:09,000
|
| 839 |
+
You see, collisions occur when two different messages produces the same hash.
|
| 840 |
+
|
| 841 |
+
211
|
| 842 |
+
00:11:09,000 --> 00:11:10,000
|
| 843 |
+
That's really bad.
|
| 844 |
+
|
| 845 |
+
212
|
| 846 |
+
00:11:11,000 --> 00:11:13,000
|
| 847 |
+
You see, you have to understand how it functions.
|
| 848 |
+
|
| 849 |
+
213
|
| 850 |
+
00:11:13,000 --> 00:11:15,000
|
| 851 |
+
And let's talk about how it functions.
|
| 852 |
+
|
| 853 |
+
214
|
| 854 |
+
00:11:15,000 --> 00:11:20,000
|
| 855 |
+
So like how do you end up with a collision.
|
| 856 |
+
|
| 857 |
+
215
|
| 858 |
+
00:11:21,000 --> 00:11:21,000
|
| 859 |
+
We.
|
| 860 |
+
|
| 861 |
+
216
|
| 862 |
+
00:11:21,000 --> 00:11:24,000
|
| 863 |
+
First of all, you have to understand the hash value.
|
| 864 |
+
|
| 865 |
+
217
|
| 866 |
+
00:11:24,000 --> 00:11:28,000
|
| 867 |
+
The hash value algorithm a hash algorithm comes in bit string.
|
| 868 |
+
|
| 869 |
+
218
|
| 870 |
+
00:11:28,000 --> 00:11:32,000
|
| 871 |
+
For example, Sha like we saw was 256.
|
| 872 |
+
|
| 873 |
+
219
|
| 874 |
+
00:11:32,000 --> 00:11:36,000
|
| 875 |
+
That means that the output that it's giving you is 256 bit.
|
| 876 |
+
|
| 877 |
+
220
|
| 878 |
+
00:11:37,000 --> 00:11:41,000
|
| 879 |
+
There's another famous one called MD5, although you shouldn't be using it.
|
| 880 |
+
|
| 881 |
+
221
|
| 882 |
+
00:11:41,000 --> 00:11:44,000
|
| 883 |
+
It was pretty famous that has 128 bit.
|
| 884 |
+
|
| 885 |
+
222
|
| 886 |
+
00:11:44,000 --> 00:11:52,000
|
| 887 |
+
And if you remember earlier in the video, when we say 128 bit 256 bits, that tells me that's those
|
| 888 |
+
|
| 889 |
+
223
|
| 890 |
+
00:11:52,000 --> 00:11:53,000
|
| 891 |
+
are the number of digits in the hash.
|
| 892 |
+
|
| 893 |
+
224
|
| 894 |
+
00:11:53,000 --> 00:11:55,000
|
| 895 |
+
So how many possible hash you can have?
|
| 896 |
+
|
| 897 |
+
225
|
| 898 |
+
00:11:55,000 --> 00:11:57,000
|
| 899 |
+
Well, the number of bits tell you that.
|
| 900 |
+
|
| 901 |
+
226
|
| 902 |
+
00:11:57,000 --> 00:12:06,000
|
| 903 |
+
So if it's 128 bit there's 2 to 128 number of hashes available to be used.
|
| 904 |
+
|
| 905 |
+
227
|
| 906 |
+
00:12:07,000 --> 00:12:12,000
|
| 907 |
+
It's not an unlimited number of hashes out there, it is just a fixed number of hashes.
|
| 908 |
+
|
| 909 |
+
228
|
| 910 |
+
00:12:12,000 --> 00:12:15,000
|
| 911 |
+
Although it's a big pool, it's still a pool.
|
| 912 |
+
|
| 913 |
+
229
|
| 914 |
+
00:12:15,000 --> 00:12:16,000
|
| 915 |
+
It's still a fixed number.
|
| 916 |
+
|
| 917 |
+
230
|
| 918 |
+
00:12:17,000 --> 00:12:22,000
|
| 919 |
+
For example, let's say I'm really, really crazy and I make a hash function.
|
| 920 |
+
|
| 921 |
+
231
|
| 922 |
+
00:12:22,000 --> 00:12:25,000
|
| 923 |
+
A hash function that's two bits.
|
| 924 |
+
|
| 925 |
+
232
|
| 926 |
+
00:12:25,000 --> 00:12:28,000
|
| 927 |
+
Two bits only gives me four possible hashes.
|
| 928 |
+
|
| 929 |
+
233
|
| 930 |
+
00:12:28,000 --> 00:12:38,000
|
| 931 |
+
So if you're using my for my hash function to to do to to hash your data with, it'll be easy to have
|
| 932 |
+
|
| 933 |
+
234
|
| 934 |
+
00:12:38,000 --> 00:12:43,000
|
| 935 |
+
multiple different data having the exact same hash because only four possible hashes.
|
| 936 |
+
|
| 937 |
+
235
|
| 938 |
+
00:12:44,000 --> 00:12:45,000
|
| 939 |
+
So.
|
| 940 |
+
|
| 941 |
+
236
|
| 942 |
+
00:12:45,000 --> 00:12:51,000
|
| 943 |
+
Because the hash functions of today uses like 128, 256, 384, 512.
|
| 944 |
+
|
| 945 |
+
237
|
| 946 |
+
00:12:52,000 --> 00:12:53,000
|
| 947 |
+
Crazy amount of hashes.
|
| 948 |
+
|
| 949 |
+
238
|
| 950 |
+
00:12:54,000 --> 00:12:57,000
|
| 951 |
+
Collisions are not very likely, but they're not impossible.
|
| 952 |
+
|
| 953 |
+
239
|
| 954 |
+
00:12:58,000 --> 00:13:00,000
|
| 955 |
+
And there is a paradox.
|
| 956 |
+
|
| 957 |
+
240
|
| 958 |
+
00:13:00,000 --> 00:13:04,000
|
| 959 |
+
I want to talk to you guys about today that makes it somewhat possible.
|
| 960 |
+
|
| 961 |
+
241
|
| 962 |
+
00:13:04,000 --> 00:13:15,000
|
| 963 |
+
So for example MD5, the hash function of MD5, MD5 is 128 bit two to the 128 is a number 38 zeros,
|
| 964 |
+
|
| 965 |
+
242
|
| 966 |
+
00:13:15,000 --> 00:13:16,000
|
| 967 |
+
37 zeros.
|
| 968 |
+
|
| 969 |
+
243
|
| 970 |
+
00:13:16,000 --> 00:13:16,000
|
| 971 |
+
I forgot this number.
|
| 972 |
+
|
| 973 |
+
244
|
| 974 |
+
00:13:16,000 --> 00:13:18,000
|
| 975 |
+
It's a crazy big number.
|
| 976 |
+
|
| 977 |
+
245
|
| 978 |
+
00:13:18,000 --> 00:13:23,000
|
| 979 |
+
So what is the probability that two different messages produce the same hash?
|
| 980 |
+
|
| 981 |
+
246
|
| 982 |
+
00:13:23,000 --> 00:13:28,000
|
| 983 |
+
It's not impossible because again there's a fixed number of hashes, but it doesn't seem likely.
|
| 984 |
+
|
| 985 |
+
247
|
| 986 |
+
00:13:30,000 --> 00:13:32,000
|
| 987 |
+
I want to show you guys a couple of things.
|
| 988 |
+
|
| 989 |
+
248
|
| 990 |
+
00:13:32,000 --> 00:13:33,000
|
| 991 |
+
First of all I want to show you a collision.
|
| 992 |
+
|
| 993 |
+
249
|
| 994 |
+
00:13:33,000 --> 00:13:36,000
|
| 995 |
+
So here is a diagram that we have.
|
| 996 |
+
|
| 997 |
+
250
|
| 998 |
+
00:13:36,000 --> 00:13:39,000
|
| 999 |
+
So this is the normal this is the collision.
|
| 1000 |
+
|
| 1001 |
+
251
|
| 1002 |
+
00:13:39,000 --> 00:13:47,000
|
| 1003 |
+
So in the normal look at the text the red fox runs across the box box and input field hashes it.
|
| 1004 |
+
|
| 1005 |
+
252
|
| 1006 |
+
00:13:47,000 --> 00:13:53,000
|
| 1007 |
+
And he gets this this this uh this output the yellow fox different message hashes to get this.
|
| 1008 |
+
|
| 1009 |
+
253
|
| 1010 |
+
00:13:53,000 --> 00:13:54,000
|
| 1011 |
+
But they're different right.
|
| 1012 |
+
|
| 1013 |
+
254
|
| 1014 |
+
00:13:54,000 --> 00:13:55,000
|
| 1015 |
+
This is normal.
|
| 1016 |
+
|
| 1017 |
+
255
|
| 1018 |
+
00:13:55,000 --> 00:13:57,000
|
| 1019 |
+
Different messages, different hash.
|
| 1020 |
+
|
| 1021 |
+
256
|
| 1022 |
+
00:13:57,000 --> 00:14:04,000
|
| 1023 |
+
The collision occurs when you take the red fox and the yellow fox to different messages, hashes it
|
| 1024 |
+
|
| 1025 |
+
257
|
| 1026 |
+
00:14:04,000 --> 00:14:05,000
|
| 1027 |
+
with the same function.
|
| 1028 |
+
|
| 1029 |
+
258
|
| 1030 |
+
00:14:05,000 --> 00:14:09,000
|
| 1031 |
+
But now all of a sudden you have the exact same hash.
|
| 1032 |
+
|
| 1033 |
+
259
|
| 1034 |
+
00:14:09,000 --> 00:14:14,000
|
| 1035 |
+
This is the collision two different messages producing the same hash function.
|
| 1036 |
+
|
| 1037 |
+
260
|
| 1038 |
+
00:14:16,000 --> 00:14:19,000
|
| 1039 |
+
Now, this is a kind of a weakness.
|
| 1040 |
+
|
| 1041 |
+
261
|
| 1042 |
+
00:14:19,000 --> 00:14:20,000
|
| 1043 |
+
All right.
|
| 1044 |
+
|
| 1045 |
+
262
|
| 1046 |
+
00:14:20,000 --> 00:14:22,000
|
| 1047 |
+
MD5 has multiple collision.
|
| 1048 |
+
|
| 1049 |
+
263
|
| 1050 |
+
00:14:22,000 --> 00:14:23,000
|
| 1051 |
+
That's what you should never use it.
|
| 1052 |
+
|
| 1053 |
+
264
|
| 1054 |
+
00:14:24,000 --> 00:14:27,000
|
| 1055 |
+
Uh, you should be using Sha 256 and above.
|
| 1056 |
+
|
| 1057 |
+
265
|
| 1058 |
+
00:14:27,000 --> 00:14:32,000
|
| 1059 |
+
An example of this I want to mention is something we call a birthday attack against passwords.
|
| 1060 |
+
|
| 1061 |
+
266
|
| 1062 |
+
00:14:32,000 --> 00:14:34,000
|
| 1063 |
+
The birthday attack is like a password thing.
|
| 1064 |
+
|
| 1065 |
+
267
|
| 1066 |
+
00:14:35,000 --> 00:14:36,000
|
| 1067 |
+
Most people know it as a password.
|
| 1068 |
+
|
| 1069 |
+
268
|
| 1070 |
+
00:14:36,000 --> 00:14:37,000
|
| 1071 |
+
I'll explain what this is to you.
|
| 1072 |
+
|
| 1073 |
+
269
|
| 1074 |
+
00:14:37,000 --> 00:14:40,000
|
| 1075 |
+
The what's called the birthday paradox.
|
| 1076 |
+
|
| 1077 |
+
270
|
| 1078 |
+
00:14:41,000 --> 00:14:46,000
|
| 1079 |
+
So I'm going to give you guys and I'm gonna explain why this is related to hashing.
|
| 1080 |
+
|
| 1081 |
+
271
|
| 1082 |
+
00:14:46,000 --> 00:14:49,000
|
| 1083 |
+
I'm going to give you guys something to think about.
|
| 1084 |
+
|
| 1085 |
+
272
|
| 1086 |
+
00:14:49,000 --> 00:14:50,000
|
| 1087 |
+
All right.
|
| 1088 |
+
|
| 1089 |
+
273
|
| 1090 |
+
00:14:50,000 --> 00:14:52,000
|
| 1091 |
+
Here's a type of a math function.
|
| 1092 |
+
|
| 1093 |
+
274
|
| 1094 |
+
00:14:52,000 --> 00:14:53,000
|
| 1095 |
+
You have to do a little bit of math.
|
| 1096 |
+
|
| 1097 |
+
275
|
| 1098 |
+
00:14:53,000 --> 00:14:55,000
|
| 1099 |
+
Don't worry it's not complex.
|
| 1100 |
+
|
| 1101 |
+
276
|
| 1102 |
+
00:14:55,000 --> 00:14:57,000
|
| 1103 |
+
If I put 30 people in a room.
|
| 1104 |
+
|
| 1105 |
+
277
|
| 1106 |
+
00:14:58,000 --> 00:15:03,000
|
| 1107 |
+
What is the probability that any two people have the exact same birthday?
|
| 1108 |
+
|
| 1109 |
+
278
|
| 1110 |
+
00:15:03,000 --> 00:15:07,000
|
| 1111 |
+
In that year there's 365 possible combinations of birthday, right?
|
| 1112 |
+
|
| 1113 |
+
279
|
| 1114 |
+
00:15:07,000 --> 00:15:11,000
|
| 1115 |
+
January 1st, January 2nd, January 3rd, 365 combinations.
|
| 1116 |
+
|
| 1117 |
+
280
|
| 1118 |
+
00:15:12,000 --> 00:15:14,000
|
| 1119 |
+
There's 30 people in the room.
|
| 1120 |
+
|
| 1121 |
+
281
|
| 1122 |
+
00:15:14,000 --> 00:15:18,000
|
| 1123 |
+
If I was to ask you guys if we were to, um.
|
| 1124 |
+
|
| 1125 |
+
282
|
| 1126 |
+
00:15:20,000 --> 00:15:25,000
|
| 1127 |
+
If we were to just grab two people that any two people, what's the probability that if we grab any
|
| 1128 |
+
|
| 1129 |
+
283
|
| 1130 |
+
00:15:25,000 --> 00:15:27,000
|
| 1131 |
+
two people, they have the same birthday?
|
| 1132 |
+
|
| 1133 |
+
284
|
| 1134 |
+
00:15:27,000 --> 00:15:29,000
|
| 1135 |
+
Would you say that number is small?
|
| 1136 |
+
|
| 1137 |
+
285
|
| 1138 |
+
00:15:29,000 --> 00:15:30,000
|
| 1139 |
+
1%, 2%.
|
| 1140 |
+
|
| 1141 |
+
286
|
| 1142 |
+
00:15:30,000 --> 00:15:31,000
|
| 1143 |
+
Would you say it's moderate?
|
| 1144 |
+
|
| 1145 |
+
287
|
| 1146 |
+
00:15:31,000 --> 00:15:33,000
|
| 1147 |
+
30, 40, 50, 60%?
|
| 1148 |
+
|
| 1149 |
+
288
|
| 1150 |
+
00:15:33,000 --> 00:15:34,000
|
| 1151 |
+
Would you say it's high?
|
| 1152 |
+
|
| 1153 |
+
289
|
| 1154 |
+
00:15:34,000 --> 00:15:34,000
|
| 1155 |
+
80?
|
| 1156 |
+
|
| 1157 |
+
290
|
| 1158 |
+
00:15:34,000 --> 00:15:35,000
|
| 1159 |
+
90%.
|
| 1160 |
+
|
| 1161 |
+
291
|
| 1162 |
+
00:15:37,000 --> 00:15:39,000
|
| 1163 |
+
Well without me giving it to you.
|
| 1164 |
+
|
| 1165 |
+
292
|
| 1166 |
+
00:15:39,000 --> 00:15:40,000
|
| 1167 |
+
Let me just show you.
|
| 1168 |
+
|
| 1169 |
+
293
|
| 1170 |
+
00:15:40,000 --> 00:15:42,000
|
| 1171 |
+
So here I have.
|
| 1172 |
+
|
| 1173 |
+
294
|
| 1174 |
+
00:15:42,000 --> 00:15:45,000
|
| 1175 |
+
I went to Wikipedia and I looked up birthday attack.
|
| 1176 |
+
|
| 1177 |
+
295
|
| 1178 |
+
00:15:45,000 --> 00:15:48,000
|
| 1179 |
+
You see, the birthday attack is a brute force.
|
| 1180 |
+
|
| 1181 |
+
296
|
| 1182 |
+
00:15:48,000 --> 00:15:49,000
|
| 1183 |
+
Is a brute force collision.
|
| 1184 |
+
|
| 1185 |
+
297
|
| 1186 |
+
00:15:49,000 --> 00:15:50,000
|
| 1187 |
+
Attack?
|
| 1188 |
+
|
| 1189 |
+
298
|
| 1190 |
+
00:15:51,000 --> 00:15:54,000
|
| 1191 |
+
It works on something we call the birthday paradox.
|
| 1192 |
+
|
| 1193 |
+
299
|
| 1194 |
+
00:15:54,000 --> 00:15:55,000
|
| 1195 |
+
Now what?
|
| 1196 |
+
|
| 1197 |
+
300
|
| 1198 |
+
00:15:55,000 --> 00:15:56,000
|
| 1199 |
+
This is.
|
| 1200 |
+
|
| 1201 |
+
301
|
| 1202 |
+
00:15:56,000 --> 00:15:57,000
|
| 1203 |
+
This is what I was just explaining.
|
| 1204 |
+
|
| 1205 |
+
302
|
| 1206 |
+
00:16:00,000 --> 00:16:05,000
|
| 1207 |
+
A scenario where a teacher with a class of 30 students actually everyone's birthday to determine whether
|
| 1208 |
+
|
| 1209 |
+
303
|
| 1210 |
+
00:16:05,000 --> 00:16:08,000
|
| 1211 |
+
any two students have the same birthday.
|
| 1212 |
+
|
| 1213 |
+
304
|
| 1214 |
+
00:16:08,000 --> 00:16:14,000
|
| 1215 |
+
Although this may seem small, the probability of one student having the same birthday as any other
|
| 1216 |
+
|
| 1217 |
+
305
|
| 1218 |
+
00:16:14,000 --> 00:16:16,000
|
| 1219 |
+
is actually 70%.
|
| 1220 |
+
|
| 1221 |
+
306
|
| 1222 |
+
00:16:16,000 --> 00:16:23,000
|
| 1223 |
+
Now, most of my students generally say 1% or 2%, but in actuality it's actually 70%.
|
| 1224 |
+
|
| 1225 |
+
307
|
| 1226 |
+
00:16:23,000 --> 00:16:24,000
|
| 1227 |
+
It's not a small number.
|
| 1228 |
+
|
| 1229 |
+
308
|
| 1230 |
+
00:16:25,000 --> 00:16:31,000
|
| 1231 |
+
In fact, if you put, I believe it's 60 people in a room, there's a 90 or 99% people percentage that
|
| 1232 |
+
|
| 1233 |
+
309
|
| 1234 |
+
00:16:31,000 --> 00:16:34,000
|
| 1235 |
+
they're going to have two, two people are going to have the same birthday.
|
| 1236 |
+
|
| 1237 |
+
310
|
| 1238 |
+
00:16:35,000 --> 00:16:40,000
|
| 1239 |
+
And if you're wondering, what the hell does that have to do with passwords or hashing collision.
|
| 1240 |
+
|
| 1241 |
+
311
|
| 1242 |
+
00:16:40,000 --> 00:16:47,000
|
| 1243 |
+
You see, the birthday paradox teaches us a very important thing about the laws of probability.
|
| 1244 |
+
|
| 1245 |
+
312
|
| 1246 |
+
00:16:47,000 --> 00:16:50,000
|
| 1247 |
+
What seems improbable is actually more probable than we believe.
|
| 1248 |
+
|
| 1249 |
+
313
|
| 1250 |
+
00:16:50,000 --> 00:16:57,000
|
| 1251 |
+
Although it seems like 30 people with 365 combinations seems like a very small likelihood, it's actually
|
| 1252 |
+
|
| 1253 |
+
314
|
| 1254 |
+
00:16:57,000 --> 00:16:58,000
|
| 1255 |
+
very likely.
|
| 1256 |
+
|
| 1257 |
+
315
|
| 1258 |
+
00:16:58,000 --> 00:17:00,000
|
| 1259 |
+
You see, how does this relate to hashing?
|
| 1260 |
+
|
| 1261 |
+
316
|
| 1262 |
+
00:17:00,000 --> 00:17:01,000
|
| 1263 |
+
Is this.
|
| 1264 |
+
|
| 1265 |
+
317
|
| 1266 |
+
00:17:02,000 --> 00:17:08,000
|
| 1267 |
+
There's two to the 128 bit number of hashes when you use an MD5 hash.
|
| 1268 |
+
|
| 1269 |
+
318
|
| 1270 |
+
00:17:08,000 --> 00:17:10,000
|
| 1271 |
+
There's an unlimited number of messages.
|
| 1272 |
+
|
| 1273 |
+
319
|
| 1274 |
+
00:17:10,000 --> 00:17:16,000
|
| 1275 |
+
The probability of two messages having the same hash seems very unlikely because there's so many hashes.
|
| 1276 |
+
|
| 1277 |
+
320
|
| 1278 |
+
00:17:16,000 --> 00:17:19,000
|
| 1279 |
+
But the birthday paradox says actually there is.
|
| 1280 |
+
|
| 1281 |
+
321
|
| 1282 |
+
00:17:19,000 --> 00:17:22,000
|
| 1283 |
+
There is no way to defeat the birthday paradox.
|
| 1284 |
+
|
| 1285 |
+
322
|
| 1286 |
+
00:17:22,000 --> 00:17:23,000
|
| 1287 |
+
There's no way to stop it.
|
| 1288 |
+
|
| 1289 |
+
323
|
| 1290 |
+
00:17:23,000 --> 00:17:27,000
|
| 1291 |
+
It's just the laws of math, except if you increase the number of birthdays.
|
| 1292 |
+
|
| 1293 |
+
324
|
| 1294 |
+
00:17:27,000 --> 00:17:32,000
|
| 1295 |
+
So instead of having 365 put 1000 combinations, then that percentage drops, that 70 goes down.
|
| 1296 |
+
|
| 1297 |
+
325
|
| 1298 |
+
00:17:32,000 --> 00:17:37,000
|
| 1299 |
+
So the way to break it is to increase the pool of possible hashes.
|
| 1300 |
+
|
| 1301 |
+
326
|
| 1302 |
+
00:17:37,000 --> 00:17:40,000
|
| 1303 |
+
Or in this come in this one pool of possible birthdays.
|
| 1304 |
+
|
| 1305 |
+
327
|
| 1306 |
+
00:17:41,000 --> 00:17:42,000
|
| 1307 |
+
Now.
|
| 1308 |
+
|
| 1309 |
+
328
|
| 1310 |
+
00:17:43,000 --> 00:17:45,000
|
| 1311 |
+
How does a birthday attack relate to passwords?
|
| 1312 |
+
|
| 1313 |
+
329
|
| 1314 |
+
00:17:45,000 --> 00:17:47,000
|
| 1315 |
+
Well, first of all, just what a heads up.
|
| 1316 |
+
|
| 1317 |
+
330
|
| 1318 |
+
00:17:47,000 --> 00:17:52,000
|
| 1319 |
+
When we get to the password section, I'm going to tell you guys remember hashing all passwords are
|
| 1320 |
+
|
| 1321 |
+
331
|
| 1322 |
+
00:17:52,000 --> 00:17:52,000
|
| 1323 |
+
hash.
|
| 1324 |
+
|
| 1325 |
+
332
|
| 1326 |
+
00:17:52,000 --> 00:17:55,000
|
| 1327 |
+
Computers don't store your passwords.
|
| 1328 |
+
|
| 1329 |
+
333
|
| 1330 |
+
00:17:56,000 --> 00:17:59,000
|
| 1331 |
+
As password as a plaintext, it stores it as hashes.
|
| 1332 |
+
|
| 1333 |
+
334
|
| 1334 |
+
00:17:59,000 --> 00:18:00,000
|
| 1335 |
+
Let me show you guys something.
|
| 1336 |
+
|
| 1337 |
+
335
|
| 1338 |
+
00:18:02,000 --> 00:18:06,000
|
| 1339 |
+
So a computer if your password is password one.
|
| 1340 |
+
|
| 1341 |
+
336
|
| 1342 |
+
00:18:06,000 --> 00:18:09,000
|
| 1343 |
+
This is what the computer stores this.
|
| 1344 |
+
|
| 1345 |
+
337
|
| 1346 |
+
00:18:11,000 --> 00:18:11,000
|
| 1347 |
+
Okay.
|
| 1348 |
+
|
| 1349 |
+
338
|
| 1350 |
+
00:18:11,000 --> 00:18:14,000
|
| 1351 |
+
It does not store your plaintext password.
|
| 1352 |
+
|
| 1353 |
+
339
|
| 1354 |
+
00:18:14,000 --> 00:18:20,000
|
| 1355 |
+
All computers, all computing systems doesn't store this plaintext.
|
| 1356 |
+
|
| 1357 |
+
340
|
| 1358 |
+
00:18:20,000 --> 00:18:21,000
|
| 1359 |
+
It stores this.
|
| 1360 |
+
|
| 1361 |
+
341
|
| 1362 |
+
00:18:22,000 --> 00:18:28,000
|
| 1363 |
+
So when you type in your password as password one, it then rehashes this and matches it to what it
|
| 1364 |
+
|
| 1365 |
+
342
|
| 1366 |
+
00:18:28,000 --> 00:18:29,000
|
| 1367 |
+
has on file.
|
| 1368 |
+
|
| 1369 |
+
343
|
| 1370 |
+
00:18:30,000 --> 00:18:35,000
|
| 1371 |
+
Remember, it's one way even if people compromise your system and steal your steal the hash, they should
|
| 1372 |
+
|
| 1373 |
+
344
|
| 1374 |
+
00:18:35,000 --> 00:18:36,000
|
| 1375 |
+
never be able to work it backwards.
|
| 1376 |
+
|
| 1377 |
+
345
|
| 1378 |
+
00:18:36,000 --> 00:18:37,000
|
| 1379 |
+
Because remember what I said?
|
| 1380 |
+
|
| 1381 |
+
346
|
| 1382 |
+
00:18:37,000 --> 00:18:43,000
|
| 1383 |
+
Hashing is one way where the birthday paradox comes into play, or the birthday attack comes into play
|
| 1384 |
+
|
| 1385 |
+
347
|
| 1386 |
+
00:18:43,000 --> 00:18:44,000
|
| 1387 |
+
is like this.
|
| 1388 |
+
|
| 1389 |
+
348
|
| 1390 |
+
00:18:45,000 --> 00:18:49,000
|
| 1391 |
+
It comes into play when your password is car, car.
|
| 1392 |
+
|
| 1393 |
+
349
|
| 1394 |
+
00:18:49,000 --> 00:18:53,000
|
| 1395 |
+
And then I come to you and it says, hey man, I guess your password.
|
| 1396 |
+
|
| 1397 |
+
350
|
| 1398 |
+
00:18:53,000 --> 00:18:54,000
|
| 1399 |
+
And you're like, okay, what is it?
|
| 1400 |
+
|
| 1401 |
+
351
|
| 1402 |
+
00:18:54,000 --> 00:18:56,000
|
| 1403 |
+
And I say, it's van, van.
|
| 1404 |
+
|
| 1405 |
+
352
|
| 1406 |
+
00:18:56,000 --> 00:18:59,000
|
| 1407 |
+
And you're like, no, it's car.
|
| 1408 |
+
|
| 1409 |
+
353
|
| 1410 |
+
00:18:59,000 --> 00:19:00,000
|
| 1411 |
+
And I said, nope, it's van.
|
| 1412 |
+
|
| 1413 |
+
354
|
| 1414 |
+
00:19:00,000 --> 00:19:01,000
|
| 1415 |
+
So you say prove it.
|
| 1416 |
+
|
| 1417 |
+
355
|
| 1418 |
+
00:19:01,000 --> 00:19:03,000
|
| 1419 |
+
So I go to the machine.
|
| 1420 |
+
|
| 1421 |
+
356
|
| 1422 |
+
00:19:03,000 --> 00:19:08,000
|
| 1423 |
+
And I type in your username and I type the word van and boom, it logs me in.
|
| 1424 |
+
|
| 1425 |
+
357
|
| 1426 |
+
00:19:08,000 --> 00:19:09,000
|
| 1427 |
+
You like me.
|
| 1428 |
+
|
| 1429 |
+
358
|
| 1430 |
+
00:19:09,000 --> 00:19:11,000
|
| 1431 |
+
I change my password so I log out.
|
| 1432 |
+
|
| 1433 |
+
359
|
| 1434 |
+
00:19:11,000 --> 00:19:15,000
|
| 1435 |
+
Then you come, you type your same username, you type the word car and you press enter and boom.
|
| 1436 |
+
|
| 1437 |
+
360
|
| 1438 |
+
00:19:15,000 --> 00:19:16,000
|
| 1439 |
+
It logs you in too.
|
| 1440 |
+
|
| 1441 |
+
361
|
| 1442 |
+
00:19:16,000 --> 00:19:17,000
|
| 1443 |
+
It's odd.
|
| 1444 |
+
|
| 1445 |
+
362
|
| 1446 |
+
00:19:17,000 --> 00:19:20,000
|
| 1447 |
+
It's two different words logging into the same account.
|
| 1448 |
+
|
| 1449 |
+
363
|
| 1450 |
+
00:19:20,000 --> 00:19:23,000
|
| 1451 |
+
It's like this one account has two different password.
|
| 1452 |
+
|
| 1453 |
+
364
|
| 1454 |
+
00:19:23,000 --> 00:19:24,000
|
| 1455 |
+
Know what's happening?
|
| 1456 |
+
|
| 1457 |
+
365
|
| 1458 |
+
00:19:24,000 --> 00:19:26,000
|
| 1459 |
+
There is the collision of where.
|
| 1460 |
+
|
| 1461 |
+
366
|
| 1462 |
+
00:19:27,000 --> 00:19:28,000
|
| 1463 |
+
Password.
|
| 1464 |
+
|
| 1465 |
+
367
|
| 1466 |
+
00:19:28,000 --> 00:19:34,000
|
| 1467 |
+
One is producing this hash and another text is producing the same hash as password one.
|
| 1468 |
+
|
| 1469 |
+
368
|
| 1470 |
+
00:19:34,000 --> 00:19:39,000
|
| 1471 |
+
The computer thinks car and van is the same thing because it's the same hash.
|
| 1472 |
+
|
| 1473 |
+
369
|
| 1474 |
+
00:19:40,000 --> 00:19:41,000
|
| 1475 |
+
That's a birthday attack.
|
| 1476 |
+
|
| 1477 |
+
370
|
| 1478 |
+
00:19:41,000 --> 00:19:42,000
|
| 1479 |
+
How do you defeat it?
|
| 1480 |
+
|
| 1481 |
+
371
|
| 1482 |
+
00:19:42,000 --> 00:19:43,000
|
| 1483 |
+
Use a big hash.
|
| 1484 |
+
|
| 1485 |
+
372
|
| 1486 |
+
00:19:43,000 --> 00:19:45,000
|
| 1487 |
+
Don't use a 128 bit hash.
|
| 1488 |
+
|
| 1489 |
+
373
|
| 1490 |
+
00:19:45,000 --> 00:19:49,000
|
| 1491 |
+
Remember I said you can only beat the birthday attack if you increase the number of birthdays.
|
| 1492 |
+
|
| 1493 |
+
374
|
| 1494 |
+
00:19:49,000 --> 00:19:50,000
|
| 1495 |
+
How do you beat it?
|
| 1496 |
+
|
| 1497 |
+
375
|
| 1498 |
+
00:19:50,000 --> 00:19:52,000
|
| 1499 |
+
Don't use the same number.
|
| 1500 |
+
|
| 1501 |
+
376
|
| 1502 |
+
00:19:52,000 --> 00:19:54,000
|
| 1503 |
+
Don't use small birthdays.
|
| 1504 |
+
|
| 1505 |
+
377
|
| 1506 |
+
00:19:54,000 --> 00:19:56,000
|
| 1507 |
+
Don't use a pool with a small amount of birthdays.
|
| 1508 |
+
|
| 1509 |
+
378
|
| 1510 |
+
00:19:56,000 --> 00:19:56,000
|
| 1511 |
+
Use a big one.
|
| 1512 |
+
|
| 1513 |
+
379
|
| 1514 |
+
00:19:56,000 --> 00:19:57,000
|
| 1515 |
+
Don't use 128.
|
| 1516 |
+
|
| 1517 |
+
380
|
| 1518 |
+
00:19:57,000 --> 00:19:58,000
|
| 1519 |
+
Use 256.
|
| 1520 |
+
|
| 1521 |
+
381
|
| 1522 |
+
00:19:58,000 --> 00:20:00,000
|
| 1523 |
+
That's the one we should be using today.
|
| 1524 |
+
|
| 1525 |
+
382
|
| 1526 |
+
00:20:00,000 --> 00:20:05,000
|
| 1527 |
+
Sha 256 all right, a lot of stuff in hashing.
|
| 1528 |
+
|
| 1529 |
+
383
|
| 1530 |
+
00:20:05,000 --> 00:20:07,000
|
| 1531 |
+
But before I go, let's do a quick recap of hashing.
|
| 1532 |
+
|
| 1533 |
+
384
|
| 1534 |
+
00:20:07,000 --> 00:20:09,000
|
| 1535 |
+
So hash is a cryptographic function.
|
| 1536 |
+
|
| 1537 |
+
385
|
| 1538 |
+
00:20:09,000 --> 00:20:13,000
|
| 1539 |
+
It takes data of any length, produces a fixed length hash.
|
| 1540 |
+
|
| 1541 |
+
386
|
| 1542 |
+
00:20:13,000 --> 00:20:14,000
|
| 1543 |
+
It's a one way thing.
|
| 1544 |
+
|
| 1545 |
+
387
|
| 1546 |
+
00:20:14,000 --> 00:20:18,000
|
| 1547 |
+
You cannot take the the hash function and turn it back into the plaintext.
|
| 1548 |
+
|
| 1549 |
+
388
|
| 1550 |
+
00:20:18,000 --> 00:20:20,000
|
| 1551 |
+
It should be quick.
|
| 1552 |
+
|
| 1553 |
+
389
|
| 1554 |
+
00:20:20,000 --> 00:20:23,000
|
| 1555 |
+
In other words, the computation should be very, very fast.
|
| 1556 |
+
|
| 1557 |
+
390
|
| 1558 |
+
00:20:23,000 --> 00:20:28,000
|
| 1559 |
+
Any change to the data results in a change to the cryptographic hash.
|
| 1560 |
+
|
| 1561 |
+
391
|
| 1562 |
+
00:20:28,000 --> 00:20:29,000
|
| 1563 |
+
Why are we doing this?
|
| 1564 |
+
|
| 1565 |
+
392
|
| 1566 |
+
00:20:29,000 --> 00:20:30,000
|
| 1567 |
+
The big word is integrity.
|
| 1568 |
+
|
| 1569 |
+
393
|
| 1570 |
+
00:20:30,000 --> 00:20:34,000
|
| 1571 |
+
We're able to detect modification on the data and determine integrity.
|
| 1572 |
+
|
| 1573 |
+
394
|
| 1574 |
+
00:20:34,000 --> 00:20:37,000
|
| 1575 |
+
And remember what collisions are the.
|
| 1576 |
+
|
| 1577 |
+
395
|
| 1578 |
+
00:20:37,000 --> 00:20:39,000
|
| 1579 |
+
We should be able to resist collisions.
|
| 1580 |
+
|
| 1581 |
+
396
|
| 1582 |
+
00:20:39,000 --> 00:20:41,000
|
| 1583 |
+
And the way we do that is by using bigger hashes.
|
| 1584 |
+
|
| 1585 |
+
397
|
| 1586 |
+
00:20:41,000 --> 00:20:46,000
|
| 1587 |
+
Collision is when two messages produce the same, the exact same hash.
|
| 1588 |
+
|
| 1589 |
+
398
|
| 1590 |
+
00:20:47,000 --> 00:20:51,000
|
| 1591 |
+
An example of this is the birthday attack, which we just which we just spoke about.
|
| 1592 |
+
|
| 1593 |
+
399
|
| 1594 |
+
00:20:51,000 --> 00:20:55,000
|
| 1595 |
+
So so remember what the characteristics of hashes.
|
| 1596 |
+
|
| 1597 |
+
400
|
| 1598 |
+
00:20:55,000 --> 00:20:59,000
|
| 1599 |
+
And now let's take a look at the different functions in the in the next video.
|
| 1600 |
+
|
07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,240 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
Okay, before I get into this, I want you guys to remember I have a table at the end of this section
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:09,000
|
| 7 |
+
that's going to summarize everything that I'm about to cover with you guys.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:09,000 --> 00:00:13,000
|
| 11 |
+
So this video we're going to be taking a look at all the different hash functions that are out there.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:13,000 --> 00:00:15,000
|
| 15 |
+
Once again, don't memorize all of this.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:15,000 --> 00:00:20,000
|
| 19 |
+
I just need you to know which ones are hash functions, which one are symmetric functions, and which
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:20,000 --> 00:00:22,000
|
| 23 |
+
ones are asymmetric functions or algorithms.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:22,000 --> 00:00:23,000
|
| 27 |
+
Let's take a look.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:23,000 --> 00:00:32,000
|
| 31 |
+
So when it comes to hashing algorithm uh Sha or the secure hash algorithm, those series is going to
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:32,000 --> 00:00:34,000
|
| 35 |
+
be the most famous one.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:34,000 --> 00:00:41,000
|
| 39 |
+
In fact Sha two, which comes the 256 bit version of it, is one of the most popular hashing function
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:41,000 --> 00:00:42,000
|
| 43 |
+
on the planet.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:43,000 --> 00:00:48,000
|
| 47 |
+
So the secure hash algorithm is a series of government hash functions.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:48,000 --> 00:00:49,000
|
| 51 |
+
This is promoted by NIST.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:49,000 --> 00:00:53,000
|
| 55 |
+
And if you know one thing in the world of security, if it's good enough for the government, it's generally
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:53,000 --> 00:00:54,000
|
| 59 |
+
good enough for us.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:54,000 --> 00:00:59,000
|
| 63 |
+
The original Sha one was 160 bit hash.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:59,000 --> 00:01:04,000
|
| 67 |
+
This one here should no longer be used because it is subject to collisions.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:04,000 --> 00:01:07,000
|
| 71 |
+
Remember, how you beat collisions is by having a bigger hash function.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:08,000 --> 00:01:11,000
|
| 75 |
+
Sha two came in a variety of sizes.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:11,000 --> 00:01:13,000
|
| 79 |
+
Uh 256 bit.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:13,000 --> 00:01:17,000
|
| 83 |
+
It came in 512 and it also was 384.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:17,000 --> 00:01:18,000
|
| 87 |
+
I think this one came in.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:18,000 --> 00:01:22,000
|
| 91 |
+
So it did came in multiple sizes.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:22,000 --> 00:01:24,000
|
| 95 |
+
Now I don't need you guys to worry about the blocks.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:24,000 --> 00:01:27,000
|
| 99 |
+
I just need you guys to know basically the bit sizes on that.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:27,000 --> 00:01:32,000
|
| 103 |
+
There was a Sha three that came out that uh, is a newer version of that.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:34,000 --> 00:01:37,000
|
| 107 |
+
One of the most famous old school one was MD5.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:37,000 --> 00:01:40,000
|
| 111 |
+
Now MD5 should not be used.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:40,000 --> 00:01:48,000
|
| 115 |
+
MD5 has a lot of collisions because it doesn't have a very large, um, output at 128 bit.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:48,000 --> 00:01:51,000
|
| 119 |
+
Although it's big in today's world, it's not big anymore.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:51,000 --> 00:01:53,000
|
| 123 |
+
It is subject to collisions.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:54,000 --> 00:02:03,000
|
| 127 |
+
Now, the other one here is a ripe re and ripe MD uh or message digest.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:03,000 --> 00:02:07,000
|
| 131 |
+
This is an alternative to the Sha algorithms that are out there.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:07,000 --> 00:02:10,000
|
| 135 |
+
And these have a variety of different block sizes.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:10,000 --> 00:02:14,000
|
| 139 |
+
Now I did put it on the text here, but I do summarize it for you guys right here.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:15,000 --> 00:02:21,000
|
| 143 |
+
Realistically, I don't need you guys to know all this last column.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:21,000 --> 00:02:23,000
|
| 147 |
+
What I do need you guys to know is to know this column.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:23,000 --> 00:02:26,000
|
| 151 |
+
Know that these are basically.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:28,000 --> 00:02:29,000
|
| 155 |
+
Uh, hash functions.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:29,000 --> 00:02:35,000
|
| 159 |
+
So on the exam, if they give you something, a scenario that you have to use this particular algorithm
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:35,000 --> 00:02:40,000
|
| 163 |
+
for, like for example, if they send your encrypted data across a network, don't select any of these
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:40,000 --> 00:02:42,000
|
| 167 |
+
because these are hash functions.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:42,000 --> 00:02:44,000
|
| 171 |
+
They don't encrypt data, right.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:44,000 --> 00:02:45,000
|
| 175 |
+
They produce hash functions.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:45,000 --> 00:02:46,000
|
| 179 |
+
They're used for integrity.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:46,000 --> 00:02:48,000
|
| 183 |
+
So that's what you should know.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:48,000 --> 00:02:53,000
|
| 187 |
+
But if you want to see what what algorithm can change, data can detect if data has been modified.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:53,000 --> 00:02:56,000
|
| 191 |
+
Those hash functions, that's what they're there for.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:56,000 --> 00:02:56,000
|
| 195 |
+
All right.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:56,000 --> 00:02:59,000
|
| 199 |
+
So don't you know don't go crazy.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:59,000 --> 00:02:59,000
|
| 203 |
+
Oh my God.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:59,000 --> 00:03:03,000
|
| 207 |
+
And you know, you just maybe this column here you should know.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:03,000 --> 00:03:04,000
|
| 211 |
+
And it's pretty easy right.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:04,000 --> 00:03:05,000
|
| 215 |
+
Because.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:05,000 --> 00:03:10,000
|
| 219 |
+
Ripemd sha md5, just the ones you're probably going to see.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:10,000 --> 00:03:13,000
|
| 223 |
+
So it's basically only three of them you really should keep in mind.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:14,000 --> 00:03:14,000
|
| 227 |
+
Okay.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:14,000 --> 00:03:20,000
|
| 231 |
+
Make sure you know these, um, as a real life security person, just remember, Sha256 should be your
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:20,000 --> 00:03:21,000
|
| 235 |
+
minimum.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:21,000 --> 00:03:28,000
|
| 239 |
+
Don't use hash functions that are generally under 256 bit in the world of security.
|
| 240 |
+
|
07 - Cryptography/013 Digital Signatures OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,636 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
So far we have covered a lot symmetric asymmetric hashing hybrid cryptography.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:10,000
|
| 7 |
+
So far we covered a lot in this topic.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:10,000 --> 00:00:14,000
|
| 11 |
+
We're going to be combining a lot of what we learned to produce a particular function that I need you
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:14,000 --> 00:00:16,000
|
| 15 |
+
guys to know, because we use it a lot.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:16,000 --> 00:00:19,000
|
| 19 |
+
And that's called a digital signature.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:19,000 --> 00:00:23,000
|
| 23 |
+
Now a digital signature is not a not a way to encrypt data.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:23,000 --> 00:00:28,000
|
| 27 |
+
So it doesn't provide confidentiality, but it's a way that when you send data to someone, they know
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:28,000 --> 00:00:33,000
|
| 31 |
+
it came from you, you can prove it came from you and it wasn't modified.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:33,000 --> 00:00:39,000
|
| 35 |
+
And a digital signature is going to utilize some of the things we learned in in asymmetric and hashing
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:39,000 --> 00:00:40,000
|
| 39 |
+
in order to get it done.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:40,000 --> 00:00:46,000
|
| 43 |
+
So in this video, I want to go through what exactly is a digital signature and what is the process?
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:46,000 --> 00:00:50,000
|
| 47 |
+
What is the process to make a signature and to verify a signature?
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:50,000 --> 00:00:51,000
|
| 51 |
+
Let's get into it.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:52,000 --> 00:00:55,000
|
| 55 |
+
So what exactly is a digital signature?
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:55,000 --> 00:01:02,000
|
| 59 |
+
Well, it's a cryptographic technique used to validate the authentic unity and integrity of a message
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:02,000 --> 00:01:03,000
|
| 63 |
+
software digital document.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:03,000 --> 00:01:09,000
|
| 67 |
+
Now a lot of times we digitally sign things like digital certificates and even PDF files.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:09,000 --> 00:01:11,000
|
| 71 |
+
Word documents can all be digitally signed.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:11,000 --> 00:01:14,000
|
| 75 |
+
Emails very famous to be digitally signed.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:14,000 --> 00:01:18,000
|
| 79 |
+
Also, when you're doing a digital signature, you must remember.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:19,000 --> 00:01:25,000
|
| 83 |
+
A digital signature is authenticity or authentication, its integrity and non-repudiation.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:25,000 --> 00:01:27,000
|
| 87 |
+
It is not confidentiality.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:27,000 --> 00:01:30,000
|
| 91 |
+
The data goes in plain text.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:30,000 --> 00:01:31,000
|
| 95 |
+
You have to remember this.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:31,000 --> 00:01:40,000
|
| 99 |
+
So if I have an email that I digitally sign and I send you that email, the email goes in plain text.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:40,000 --> 00:01:43,000
|
| 103 |
+
That means if if all I did was digitally sign it.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:44,000 --> 00:01:46,000
|
| 107 |
+
And I sent it to you.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:46,000 --> 00:01:47,000
|
| 111 |
+
And a hacker sniffs the line.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:47,000 --> 00:01:50,000
|
| 115 |
+
The hacker would be able to read the email because the email is not encrypted.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:50,000 --> 00:01:56,000
|
| 119 |
+
But when you receive it, you'll know that it came from me.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:57,000 --> 00:02:01,000
|
| 123 |
+
I wouldn't be able to deny that it came from me.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:01,000 --> 00:02:02,000
|
| 127 |
+
Non-repudiation.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:02,000 --> 00:02:06,000
|
| 131 |
+
And you're going to be 100% sure it was never modified.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:06,000 --> 00:02:07,000
|
| 135 |
+
All right.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:07,000 --> 00:02:09,000
|
| 139 |
+
So that's these three things.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:09,000 --> 00:02:11,000
|
| 143 |
+
Confirms the signature was created by a sender.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:11,000 --> 00:02:14,000
|
| 147 |
+
So you'll know it came from me.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:14,000 --> 00:02:17,000
|
| 151 |
+
And I can't deny that it came from me.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:17,000 --> 00:02:17,000
|
| 155 |
+
All right.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:17,000 --> 00:02:22,000
|
| 159 |
+
So the authenticity, the non-repudiation, and then you'll know it was never modified.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:22,000 --> 00:02:24,000
|
| 163 |
+
That's the point that you guys need to get.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:25,000 --> 00:02:29,000
|
| 167 |
+
Once again, digital signatures does not encrypt the data.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:29,000 --> 00:02:31,000
|
| 171 |
+
The data is actually transferred in plain text.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:31,000 --> 00:02:34,000
|
| 175 |
+
Now, if you want to encrypt the data, well, that's a whole different thing.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:34,000 --> 00:02:41,000
|
| 179 |
+
Maybe then you can combine with SSL, IPsec or other types of secure, secure algorithms.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:41,000 --> 00:02:45,000
|
| 183 |
+
But if you're just using digital signatures, you're not going to get that.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:46,000 --> 00:02:52,000
|
| 187 |
+
Now in this video, I want to talk to you guys about the creation and the verification of it.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:52,000 --> 00:03:00,000
|
| 191 |
+
I do have all the texts listed here, but I have the, uh, I have a process that I drew out that I
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:00,000 --> 00:03:02,000
|
| 195 |
+
want to go over with you that covers all of this.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:02,000 --> 00:03:07,000
|
| 199 |
+
So if you're watching, if you're reading this instead of watching it, well, you guys can read this,
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:07,000 --> 00:03:12,000
|
| 203 |
+
but since you're with me, I'm going to explain it to you in this particular.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:14,000 --> 00:03:15,000
|
| 207 |
+
In this.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:15,000 --> 00:03:16,000
|
| 211 |
+
Uh, where is my.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:16,000 --> 00:03:17,000
|
| 215 |
+
Here we go.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:17,000 --> 00:03:18,000
|
| 219 |
+
In this process.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:18,000 --> 00:03:20,000
|
| 223 |
+
So I watch you guys watch this.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:20,000 --> 00:03:25,000
|
| 227 |
+
So I'm going to show you how we are going to generate a signature.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:26,000 --> 00:03:26,000
|
| 231 |
+
Okay.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:26,000 --> 00:03:28,000
|
| 235 |
+
We're going to generate a digital signature.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:28,000 --> 00:03:30,000
|
| 239 |
+
We're going to attach it to a document send it to the receiver.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:30,000 --> 00:03:31,000
|
| 243 |
+
Let's see how this is done.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:31,000 --> 00:03:33,000
|
| 247 |
+
So here we have the sender and the.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:35,000 --> 00:03:37,000
|
| 251 |
+
And the receiver.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:37,000 --> 00:03:42,000
|
| 255 |
+
Mary I'm always sending Mary things because okay, so here's how it's done okay.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:43,000 --> 00:03:46,000
|
| 259 |
+
You take a plain text message?
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:46,000 --> 00:03:48,000
|
| 263 |
+
This is the message.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:48,000 --> 00:03:53,000
|
| 267 |
+
And then what you're going to do is you're going to hash it, hash the entire message.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:53,000 --> 00:03:58,000
|
| 271 |
+
And this produces that cryptographic hash that, remember, if you remember in the hashing video was
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:58,000 --> 00:03:59,000
|
| 275 |
+
just a string of characters.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:59,000 --> 00:04:01,000
|
| 279 |
+
Basically it produces the digest.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:01,000 --> 00:04:03,000
|
| 283 |
+
Remember the digest hash.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:03,000 --> 00:04:03,000
|
| 287 |
+
Same thing.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:04,000 --> 00:04:15,000
|
| 291 |
+
Then what the sender does is the sender encrypts this digest with the sender's private key.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:16,000 --> 00:04:18,000
|
| 295 |
+
That is.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:18,000 --> 00:04:18,000
|
| 299 |
+
All right.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:18,000 --> 00:04:20,000
|
| 303 |
+
Then they're using an RSA key here.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:20,000 --> 00:04:22,000
|
| 307 |
+
That is the digital signature.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:23,000 --> 00:04:24,000
|
| 311 |
+
So let's get this straight.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:25,000 --> 00:04:26,000
|
| 315 |
+
If I'm the sender.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:26,000 --> 00:04:27,000
|
| 319 |
+
I took the message.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:28,000 --> 00:04:30,000
|
| 323 |
+
I hashed it.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:30,000 --> 00:04:34,000
|
| 327 |
+
I did encrypt the hash with my private key.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:34,000 --> 00:04:35,000
|
| 331 |
+
Not my public key.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:36,000 --> 00:04:37,000
|
| 335 |
+
My private key.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:37,000 --> 00:04:38,000
|
| 339 |
+
Why the private key?
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:38,000 --> 00:04:44,000
|
| 343 |
+
Because the only person in the world that has my private key is me.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:44,000 --> 00:04:46,000
|
| 347 |
+
No one else.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:46,000 --> 00:04:52,000
|
| 351 |
+
So a digital signature in its purest form is an encrypted hash.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:52,000 --> 00:04:53,000
|
| 355 |
+
Really all it is?
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:53,000 --> 00:04:56,000
|
| 359 |
+
It's encrypted with an asymmetric algorithm.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:56,000 --> 00:04:58,000
|
| 363 |
+
In this one they're using RSA.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:58,000 --> 00:05:00,000
|
| 367 |
+
You can also use ECC here.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:00,000 --> 00:05:08,000
|
| 371 |
+
So what I do is I take this digital signature and I attach it to the document and I send it to the receiver.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:10,000 --> 00:05:13,000
|
| 375 |
+
Mary has the document okay.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:14,000 --> 00:05:15,000
|
| 379 |
+
And the digital signature.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:15,000 --> 00:05:18,000
|
| 383 |
+
But remember it's all going in plain text signatures.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:18,000 --> 00:05:20,000
|
| 387 |
+
Everything is in plain text.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:20,000 --> 00:05:21,000
|
| 391 |
+
What does Mary do?
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:21,000 --> 00:05:23,000
|
| 395 |
+
So Mary is like, okay, I got this signature.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:23,000 --> 00:05:27,000
|
| 399 |
+
Mary is like, okay, I need to verify, you know, that this actually came from Andy.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:27,000 --> 00:05:28,000
|
| 403 |
+
How is she going to do it?
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:28,000 --> 00:05:29,000
|
| 407 |
+
Next slide.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:30,000 --> 00:05:31,000
|
| 411 |
+
How does she do it?
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:31,000 --> 00:05:31,000
|
| 415 |
+
Well.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:32,000 --> 00:05:33,000
|
| 419 |
+
Here's what she's going to do.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:34,000 --> 00:05:37,000
|
| 423 |
+
So receiver again.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:37,000 --> 00:05:37,000
|
| 427 |
+
Mary.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:40,000 --> 00:05:46,000
|
| 431 |
+
Mary has to go through a couple of things, but Mary does is she takes this digitally signed message.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:46,000 --> 00:05:49,000
|
| 435 |
+
She removes the digital signature from it.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:05:49,000 --> 00:05:51,000
|
| 439 |
+
So now she has the plain text message.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:05:51,000 --> 00:05:58,000
|
| 443 |
+
She then hashes it with the same algorithm that I used to hash the original message, and she ends up
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:05:58,000 --> 00:05:58,000
|
| 447 |
+
with a digest.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:05:59,000 --> 00:06:02,000
|
| 451 |
+
She then takes the digital signature right?
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:02,000 --> 00:06:09,000
|
| 455 |
+
And she decrypts it with my the sender's.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:09,000 --> 00:06:11,000
|
| 459 |
+
Public key.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:11,000 --> 00:06:12,000
|
| 463 |
+
Why the sender's public key?
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:12,000 --> 00:06:19,000
|
| 467 |
+
Because, remember, in the generation, it was the sender's private key that was used to.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:20,000 --> 00:06:23,000
|
| 471 |
+
Encrypt the actual hash.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:23,000 --> 00:06:28,000
|
| 475 |
+
So what she's doing here is she's decrypting the signature with the public key.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:29,000 --> 00:06:32,000
|
| 479 |
+
If the private encrypts, the public has to decrypt that.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:33,000 --> 00:06:36,000
|
| 483 |
+
Provides the message digest.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:36,000 --> 00:06:41,000
|
| 487 |
+
So what she's going to do now is she's going to compare the hash that she generated from the message,
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:06:41,000 --> 00:06:45,000
|
| 491 |
+
and she's going to compare the hash that was generated from the signature she just decrypted.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:06:45,000 --> 00:06:53,000
|
| 495 |
+
And she's going to see do they compare if the message is from the digital signatures matches.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:06:54,000 --> 00:06:54,000
|
| 499 |
+
Right.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:06:54,000 --> 00:06:58,000
|
| 503 |
+
If the if this digest matches this digest, then it could be trusted by.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:06:59,000 --> 00:07:00,000
|
| 507 |
+
Well.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:01,000 --> 00:07:05,000
|
| 511 |
+
If the two digests are matching, it shows that the message was never modified.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:06,000 --> 00:07:06,000
|
| 515 |
+
Right.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:06,000 --> 00:07:08,000
|
| 519 |
+
Because if there's any modification to digest would change.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:08,000 --> 00:07:13,000
|
| 523 |
+
And she knows 100% that it came from me.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:13,000 --> 00:07:13,000
|
| 527 |
+
Why?
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:13,000 --> 00:07:17,000
|
| 531 |
+
Because she used my public key to decrypt that.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:17,000 --> 00:07:20,000
|
| 535 |
+
If she had used somebody else public key, it would never match.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:20,000 --> 00:07:23,000
|
| 539 |
+
It would look like more garbage or more ciphertext.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:24,000 --> 00:07:27,000
|
| 543 |
+
So that is the process of a digital signature.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:07:28,000 --> 00:07:31,000
|
| 547 |
+
Now digital signatures are widely used.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:07:31,000 --> 00:07:34,000
|
| 551 |
+
Now, if you by the way, if you don't understand this process and you want to do it, you know, watch
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:07:34,000 --> 00:07:35,000
|
| 555 |
+
this video a couple of times.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:07:35,000 --> 00:07:38,000
|
| 559 |
+
But digital signatures are widely used.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:07:38,000 --> 00:07:41,000
|
| 563 |
+
In fact, there's a whole standard on it.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:07:41,000 --> 00:07:46,000
|
| 567 |
+
So one time that you may want to be familiar with is something we call the DSS or the digital signature
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:07:46,000 --> 00:07:52,000
|
| 571 |
+
standard, because when you produce a signature, the person has to know what algorithm you use, right?
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:07:52,000 --> 00:07:55,000
|
| 575 |
+
They have to know, did he use Sha256?
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:07:55,000 --> 00:07:55,000
|
| 579 |
+
512.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:07:55,000 --> 00:08:03,000
|
| 583 |
+
Sha Sha two Sha three uh, you could use ECC as the asymmetric or RSA.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:08:04,000 --> 00:08:07,000
|
| 587 |
+
So there is a standard for this, right?
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:08:07,000 --> 00:08:13,000
|
| 591 |
+
So NSA created the digital digital signature algorithm.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:08:13,000 --> 00:08:16,000
|
| 595 |
+
The digital signature algorithm utilizes either.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:08:16,000 --> 00:08:20,000
|
| 599 |
+
So the DSA is either it's shot 2 or 3.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:08:20,000 --> 00:08:28,000
|
| 603 |
+
With RSA there's another one called Ecdsa which is instead of using RSA they use elliptic curve.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:08:28,000 --> 00:08:28,000
|
| 607 |
+
All right.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:08:28,000 --> 00:08:32,000
|
| 611 |
+
So just be familiar that there is a signature standard for this.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:08:33,000 --> 00:08:36,000
|
| 615 |
+
Digital signatures are really important digital signatures.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:08:36,000 --> 00:08:43,000
|
| 619 |
+
When somebody signs a document you are 100% sure it came from that person and it was never modified.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:08:43,000 --> 00:08:47,000
|
| 623 |
+
You have to remember that because I'm about to bring everything together when we talk about public key
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:08:47,000 --> 00:08:48,000
|
| 627 |
+
infrastructure.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:08:48,000 --> 00:08:51,000
|
| 631 |
+
So remember that once a digital signature is done.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:08:52,000 --> 00:08:59,000
|
| 635 |
+
You're 100% sure that it came from that person and it was never modified.
|
| 636 |
+
|
07 - Cryptography/014 Intro to PKI OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,124 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:04,000
|
| 3 |
+
In this video, I want to start the discussion of the public key infrastructure.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:04,000 --> 00:00:10,000
|
| 7 |
+
But before we get into that, I want to go to Amazon and I want to clear up some things about Amazon
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:10,000 --> 00:00:11,000
|
| 11 |
+
that we should know.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:11,000 --> 00:00:13,000
|
| 15 |
+
Before we get into this topic, let's take a look.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:13,000 --> 00:00:16,000
|
| 19 |
+
So here I am at Amazon.com.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:16,000 --> 00:00:19,000
|
| 23 |
+
Now the question is going to be how do I know?
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:19,000 --> 00:00:24,000
|
| 27 |
+
How does this computer know that this is Amazon.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:27,000
|
| 31 |
+
Like do you trust the browser?
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:27,000 --> 00:00:34,000
|
| 35 |
+
Okay, it says Amazon.com on it, but how does this computer know that this is Amazon.com?
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:34,000 --> 00:00:36,000
|
| 39 |
+
Is there a trust factor?
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:36,000 --> 00:00:41,000
|
| 43 |
+
Did Amazon tell this computer something that says, hey, I'm Amazon.com and the computer is like,
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:41,000 --> 00:00:45,000
|
| 47 |
+
okay, well, I guess you are, but how can the machine verify that?
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:46,000 --> 00:00:51,000
|
| 51 |
+
Well, you guys probably already know the answer to this is because it has a certificate.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:51,000 --> 00:00:55,000
|
| 55 |
+
This connection is secured using TLS.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:55,000 --> 00:00:58,000
|
| 59 |
+
And how do we know connections are secured?
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:58,000 --> 00:01:00,000
|
| 63 |
+
Well, on most browsers, if not all.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:00,000 --> 00:01:08,000
|
| 67 |
+
When you look at a connection like on Amazon, you'll notice that we have a little lock icon.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:08,000 --> 00:01:10,000
|
| 71 |
+
If I go to this icon, I click on it.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:10,000 --> 00:01:12,000
|
| 75 |
+
It says the connection is secure.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:12,000 --> 00:01:15,000
|
| 79 |
+
I click here and it says the certificate is valid.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:15,000 --> 00:01:19,000
|
| 83 |
+
But what exactly is this particular certificate?
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:19,000 --> 00:01:23,000
|
| 87 |
+
What is the purpose of this certificate and what you know?
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:23,000 --> 00:01:30,000
|
| 91 |
+
What exactly is it doing that makes this computer trust that this is Amazon.com?
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:31,000 --> 00:01:39,000
|
| 95 |
+
A certificate is basically nothing more than a document that contains Amazon's public key and a signature
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:39,000 --> 00:01:43,000
|
| 99 |
+
from a certificate authority saying that that's actually Amazon in a nutshell.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:43,000 --> 00:01:44,000
|
| 103 |
+
That's what it is.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:44,000 --> 00:01:51,000
|
| 107 |
+
But in this section of the course, I'm going to go in depth into more into all the fields on that certificate.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:51,000 --> 00:01:57,000
|
| 111 |
+
What exactly is a certificate authority and why is, you know, why do we need it?
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:57,000 --> 00:02:01,000
|
| 115 |
+
Why is it so important that your connection be trusted or secure?
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:01,000 --> 00:02:02,000
|
| 119 |
+
Okay.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:02,000 --> 00:02:05,000
|
| 123 |
+
So let's go ahead and get started in this section.
|
| 124 |
+
|
07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,1176 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:06,000
|
| 3 |
+
In this video, I'm going to be going over the SSL handshake, something that you really have to understand,
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:06,000 --> 00:00:10,000
|
| 7 |
+
not just for your exam, but exactly how this cryptography work.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:10,000 --> 00:00:17,000
|
| 11 |
+
When you buy something on Amazon or any website or any website that is secured using TLS or SSL.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:17,000 --> 00:00:22,000
|
| 15 |
+
Now for this course and in particular this section, TLS and SSL is the same thing.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:22,000 --> 00:00:26,000
|
| 19 |
+
So if I ever say SSL, TLS remember something SSL is not used anymore.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:26,000 --> 00:00:31,000
|
| 23 |
+
SSL is replaced by TLS, but a lot of people still reference it.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:31,000 --> 00:00:34,000
|
| 27 |
+
Like if you go online, you Google SSL certificate.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:34,000 --> 00:00:36,000
|
| 31 |
+
They're not really SSL, they're all TLS certificate.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:37,000 --> 00:00:42,000
|
| 35 |
+
So for argument's sake, we'll just say we'll just use the terms SSL for the remainder of the course.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:42,000 --> 00:00:44,000
|
| 39 |
+
Remember it is actually TLS.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:44,000 --> 00:00:46,000
|
| 43 |
+
Now let's get started.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:46,000 --> 00:00:49,000
|
| 47 |
+
So in this video we want to talk about the SSL handshake.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:49,000 --> 00:00:55,000
|
| 51 |
+
Now the presentation that I'm going to be using the diagram I'm going to be using comes from Ibm.com.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:55,000 --> 00:01:01,000
|
| 55 |
+
And that particular link I will be sharing with you guys on the slide.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:01,000 --> 00:01:06,000
|
| 59 |
+
And I want to show you guys what that looks like now, so you can check it out whenever you get a minute.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:06,000 --> 00:01:08,000
|
| 63 |
+
Uh, here's Ibm.com.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:09,000 --> 00:01:12,000
|
| 67 |
+
This was last updated 2021 the SSL handshake.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:12,000 --> 00:01:12,000
|
| 71 |
+
So I took this.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:12,000 --> 00:01:13,000
|
| 75 |
+
I put it on the slide.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:13,000 --> 00:01:18,000
|
| 79 |
+
Of course, I put the link here for you guys to review it also, and I want to go over this with you
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:19,000 --> 00:01:21,000
|
| 83 |
+
if you're asking yourself well why?
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:21,000 --> 00:01:25,000
|
| 87 |
+
Because this is going to explain to you at a high level overview.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:25,000 --> 00:01:29,000
|
| 91 |
+
Exactly how does a connection work?
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:29,000 --> 00:01:36,000
|
| 95 |
+
Like when you go to Amazon.com and you try to purchase something, you go to Yahoo YouTube.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:36,000 --> 00:01:37,000
|
| 99 |
+
It doesn't matter.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:37,000 --> 00:01:39,000
|
| 103 |
+
They're all secure sites.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:39,000 --> 00:01:43,000
|
| 107 |
+
In fact, all sites on the internet right now are secured using SSL.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:43,000 --> 00:01:46,000
|
| 111 |
+
How exactly this whole encryption process work?
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:46,000 --> 00:01:47,000
|
| 115 |
+
Now I want to point out something.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:47,000 --> 00:01:52,000
|
| 119 |
+
The SSL handshake presentation that I'm using from IBM is a high level.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:52,000 --> 00:01:55,000
|
| 123 |
+
It's not very detailed and it's not very technical.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:55,000 --> 00:01:56,000
|
| 127 |
+
For your exam.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:56,000 --> 00:01:58,000
|
| 131 |
+
You don't need to be detailed and technical.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:59,000 --> 00:02:02,000
|
| 135 |
+
If you take my course, I'll get more in depth into it.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:02,000 --> 00:02:04,000
|
| 139 |
+
But for this course you don't need that.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:04,000 --> 00:02:08,000
|
| 143 |
+
You just need to have a good understanding or a high level overview understanding.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:08,000 --> 00:02:09,000
|
| 147 |
+
Let's get started on it.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:09,000 --> 00:02:18,000
|
| 151 |
+
So I go to Amazon.com and here I am at Amazon and I can see that my connection is secure.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:18,000 --> 00:02:21,000
|
| 155 |
+
And if you notice is it secure.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:21,000 --> 00:02:22,000
|
| 159 |
+
Yeah, it's fully secured.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:22,000 --> 00:02:25,000
|
| 163 |
+
Because if you notice I have an Https right here.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:25,000 --> 00:02:28,000
|
| 167 |
+
So this is utilizing SSL.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:28,000 --> 00:02:31,000
|
| 171 |
+
Now the question is going to be how do I know.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:31,000 --> 00:02:32,000
|
| 175 |
+
Like it's actually working.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:32,000 --> 00:02:34,000
|
| 179 |
+
And you know what's happening in the background.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:34,000 --> 00:02:40,000
|
| 183 |
+
Well one of the things is that every single website you go to that is secure is going to have this little
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:40,000 --> 00:02:41,000
|
| 187 |
+
lock icon.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:41,000 --> 00:02:42,000
|
| 191 |
+
So I'm going to click on this little lock icon.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:42,000 --> 00:02:46,000
|
| 195 |
+
This lock icon tells me the connection is secure.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:46,000 --> 00:02:49,000
|
| 199 |
+
And you can't have a secure connection without a certificate.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:49,000 --> 00:02:52,000
|
| 203 |
+
So I'm going to go to connection to secure certificate is valid.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:52,000 --> 00:02:53,000
|
| 207 |
+
I'm just going to click on this.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:53,000 --> 00:02:56,000
|
| 211 |
+
This is Amazon certificate.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:56,000 --> 00:02:58,000
|
| 215 |
+
Now what exactly is a certificate.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:58,000 --> 00:03:04,000
|
| 219 |
+
Well a certificate really serves two main purpose in the world of encryption.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:04,000 --> 00:03:09,000
|
| 223 |
+
Number one, it serves as a trusted as an external validation of trust.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:09,000 --> 00:03:15,000
|
| 227 |
+
So right now Amazon is not saying that I'm Amazon because I'm Amazon.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:16,000 --> 00:03:20,000
|
| 231 |
+
Amazon is telling your computer that it's Amazon.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:20,000 --> 00:03:24,000
|
| 235 |
+
Not because I said it's Amazon or because Amazon said it's Amazon.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:24,000 --> 00:03:31,000
|
| 239 |
+
It's saying that because this authority Digicert says that this is Amazon.com and this is important.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:31,000 --> 00:03:35,000
|
| 243 |
+
External validation creates trust.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:35,000 --> 00:03:36,000
|
| 247 |
+
Let me explain this to you.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:37,000 --> 00:03:40,000
|
| 251 |
+
So I'm Andrew Ramsdale okay.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:40,000 --> 00:03:44,000
|
| 255 |
+
I'm the guy with the 66 certifications, the world's best selling book.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:45,000 --> 00:03:47,000
|
| 259 |
+
But do you know that for sure?
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:47,000 --> 00:03:49,000
|
| 263 |
+
Do you know if I'm that person?
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:49,000 --> 00:03:54,000
|
| 267 |
+
There is a guy that wrote the world's best selling book on Amazon for project management.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:54,000 --> 00:03:58,000
|
| 271 |
+
There is a guy that made a, you know, a lot of different videos and has helped hundreds of thousands
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:58,000 --> 00:04:02,000
|
| 275 |
+
of people pass exams, but am I that person?
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:02,000 --> 00:04:03,000
|
| 279 |
+
Do you trust me?
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:03,000 --> 00:04:05,000
|
| 283 |
+
If I told you I'm Andrew, do you?
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:05,000 --> 00:04:06,000
|
| 287 |
+
How do you know?
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:06,000 --> 00:04:09,000
|
| 291 |
+
How do you know I am that person?
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:09,000 --> 00:04:10,000
|
| 295 |
+
How do you.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:10,000 --> 00:04:12,000
|
| 299 |
+
You know I am that entity.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:13,000 --> 00:04:15,000
|
| 303 |
+
Well, I'm just telling you I am.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:15,000 --> 00:04:16,000
|
| 307 |
+
Is that okay if I tell you?
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:16,000 --> 00:04:19,000
|
| 311 |
+
Or would you like for me to produce my driver's license?
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:19,000 --> 00:04:20,000
|
| 315 |
+
Like if I told you.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:20,000 --> 00:04:21,000
|
| 319 |
+
Okay.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:21,000 --> 00:04:23,000
|
| 323 |
+
Here's my driver's license.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:23,000 --> 00:04:24,000
|
| 327 |
+
Would you believe me then?
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:25,000 --> 00:04:27,000
|
| 331 |
+
So if you say yes, okay.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:27,000 --> 00:04:34,000
|
| 335 |
+
If you show me your license, that shows me that your Andrew and that picture matches you, then you,
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:34,000 --> 00:04:36,000
|
| 339 |
+
then you're more likely or you will believe it.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:36,000 --> 00:04:41,000
|
| 343 |
+
That tells me something that tells me that you don't trust me.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:41,000 --> 00:04:44,000
|
| 347 |
+
You trust the DMV.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:44,000 --> 00:04:46,000
|
| 351 |
+
You have a trust with the DMV.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:46,000 --> 00:04:53,000
|
| 355 |
+
And if the DMV says that this guy is Andrew, then you trust that you're like, okay, that that guy
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:53,000 --> 00:04:54,000
|
| 359 |
+
must be Andrew.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:54,000 --> 00:04:56,000
|
| 363 |
+
Do you understand what I'm saying here?
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:56,000 --> 00:05:00,000
|
| 367 |
+
What I'm trying to tell you is you don't have a trust with me.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:00,000 --> 00:05:02,000
|
| 371 |
+
You have a trust with the DMV.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:02,000 --> 00:05:08,000
|
| 375 |
+
And because the DMV is saying that I'm Andrew now, you believe, okay, he's Andrew, but you don't
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:08,000 --> 00:05:10,000
|
| 379 |
+
believe a word that comes out of my mouth.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:10,000 --> 00:05:13,000
|
| 383 |
+
You believe what the DMV is saying?
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:13,000 --> 00:05:15,000
|
| 387 |
+
And why do you believe the DMV?
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:15,000 --> 00:05:16,000
|
| 391 |
+
That's the question.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:16,000 --> 00:05:18,000
|
| 395 |
+
Why do you believe the DMV?
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:18,000 --> 00:05:25,000
|
| 399 |
+
Well, because I couldn't get the license if I didn't show my passport.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:25,000 --> 00:05:27,000
|
| 403 |
+
Bank statements.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:27,000 --> 00:05:29,000
|
| 407 |
+
Uh, I forgot all the documents.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:29,000 --> 00:05:29,000
|
| 411 |
+
Right?
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:29,000 --> 00:05:30,000
|
| 415 |
+
You got to get in New York.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:30,000 --> 00:05:31,000
|
| 419 |
+
You got to get all these points.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:31,000 --> 00:05:32,000
|
| 423 |
+
Right.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:32,000 --> 00:05:34,000
|
| 427 |
+
So I had to show all these identity documents.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:34,000 --> 00:05:37,000
|
| 431 |
+
And that's the reason why you trust the DMV.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:37,000 --> 00:05:40,000
|
| 435 |
+
Well, you see, in computers, it's the same thing.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:05:41,000 --> 00:05:42,000
|
| 439 |
+
Computers.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:05:42,000 --> 00:05:45,000
|
| 443 |
+
Don't trust a website to say it's a web.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:05:45,000 --> 00:05:48,000
|
| 447 |
+
It doesn't trust the website to say it's that website.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:05:49,000 --> 00:05:50,000
|
| 451 |
+
It trusses.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:05:50,000 --> 00:05:55,000
|
| 455 |
+
Your computer has a pre list of authorities that it trusts.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:05:55,000 --> 00:05:57,000
|
| 459 |
+
Quote unquote DMVs.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:05:57,000 --> 00:05:59,000
|
| 463 |
+
These are going to be called certificate authorities.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:05:59,000 --> 00:06:02,000
|
| 467 |
+
Your computer has a pre list of certificate authorities that it trusts.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:02,000 --> 00:06:07,000
|
| 471 |
+
Similarly to how your mind has a list of people that it trusts like DMVs.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:08,000 --> 00:06:14,000
|
| 475 |
+
So when these authorities give out, quote unquote, driver's license, we'll call them certificates,
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:14,000 --> 00:06:16,000
|
| 479 |
+
two different websites.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:16,000 --> 00:06:21,000
|
| 483 |
+
When your computer go to them, your computer is like, hey, how do I know this is Amazon?
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:21,000 --> 00:06:26,000
|
| 487 |
+
And then you look at your computer, looks at the certificate and say, well, how do I know this is
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:06:26,000 --> 00:06:26,000
|
| 491 |
+
Amazon?
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:06:26,000 --> 00:06:31,000
|
| 495 |
+
Well, it's coming from somebody I trust Digicert in particular.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:06:31,000 --> 00:06:33,000
|
| 499 |
+
And how do I know this is Amazon?
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:06:33,000 --> 00:06:43,000
|
| 503 |
+
Because Digicert is saying that this is Amazon and because your computer is able to trust.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:06:43,000 --> 00:06:46,000
|
| 507 |
+
Uh digicert you now trust that this is Amazon.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:06:46,000 --> 00:06:48,000
|
| 511 |
+
That's how this game works.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:06:49,000 --> 00:06:54,000
|
| 515 |
+
There are certain websites where there's something called a self-signed certificate.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:06:54,000 --> 00:06:55,000
|
| 519 |
+
We'll talk more about this later.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:06:55,000 --> 00:07:00,000
|
| 523 |
+
But self-signed certificates is when the company it's trust it's issued by Amazon to Amazon to Amazon
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:00,000 --> 00:07:01,000
|
| 527 |
+
is saying I'm Amazon.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:01,000 --> 00:07:04,000
|
| 531 |
+
You don't trust that a lot of people don't trust self-signed certificates.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:04,000 --> 00:07:08,000
|
| 535 |
+
In fact, when internal organizations do it internally, it's not considered external trust because
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:08,000 --> 00:07:10,000
|
| 539 |
+
nobody trusts it externally.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:10,000 --> 00:07:11,000
|
| 543 |
+
Self-signed.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:07:11,000 --> 00:07:15,000
|
| 547 |
+
That's like me making my own ID it's like, hey, you trust I'm Andrew when I here is an ID that I made
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:07:15,000 --> 00:07:16,000
|
| 551 |
+
on my computer last time.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:07:16,000 --> 00:07:17,000
|
| 555 |
+
It says I'm Andrew.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:07:17,000 --> 00:07:18,000
|
| 559 |
+
Do you trust that?
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:07:18,000 --> 00:07:18,000
|
| 563 |
+
No.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:07:18,000 --> 00:07:22,000
|
| 567 |
+
You trust the driver's license because it comes from the DMV.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:07:23,000 --> 00:07:25,000
|
| 571 |
+
So that's this concept of trust.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:07:25,000 --> 00:07:27,000
|
| 575 |
+
That's why trust is important.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:07:27,000 --> 00:07:34,000
|
| 579 |
+
Your computer needs to have some kind of external validation that this is Amazon.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:07:34,000 --> 00:07:35,000
|
| 583 |
+
And what's doing that.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:07:35,000 --> 00:07:39,000
|
| 587 |
+
The certificate is doing that now a certificate I mentioned.
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:07:39,000 --> 00:07:39,000
|
| 591 |
+
It's two things.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:07:39,000 --> 00:07:46,000
|
| 595 |
+
Not just establishing that trust, but the certificate is a way to give the public key.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:07:46,000 --> 00:07:49,000
|
| 599 |
+
And that's important because that's going to become part of this handshake.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:07:49,000 --> 00:07:50,000
|
| 603 |
+
And I want to show you guys that.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:07:51,000 --> 00:07:57,000
|
| 607 |
+
So by looking if I go to details on this certificate on here.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:07:57,000 --> 00:07:59,000
|
| 611 |
+
So this is the Amazon certificate that we have.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:07:59,000 --> 00:08:02,000
|
| 615 |
+
And you notice I have a variety of fields here.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:08:02,000 --> 00:08:11,000
|
| 619 |
+
So if I go down and I look into all of these fields that is listed here notice subject public key info.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:08:12,000 --> 00:08:14,000
|
| 623 |
+
Subjects public key algorithm.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:08:14,000 --> 00:08:17,000
|
| 627 |
+
It's an RSA key that they're using.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:08:17,000 --> 00:08:19,000
|
| 631 |
+
Remember RSA is asymmetric.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:08:19,000 --> 00:08:22,000
|
| 635 |
+
But here is Amazon's actual public key.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:08:22,000 --> 00:08:25,000
|
| 639 |
+
This is a it's written it looks weird.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:08:25,000 --> 00:08:29,000
|
| 643 |
+
It's written in a hex but it's a 2048 bit RSA key.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:08:29,000 --> 00:08:32,000
|
| 647 |
+
This is Amazon's actual public key.
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:08:33,000 --> 00:08:35,000
|
| 651 |
+
Remember there is a public and a private key.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:08:35,000 --> 00:08:41,000
|
| 655 |
+
So Amazon is allowing the transport of their public key to the world.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:08:41,000 --> 00:08:47,000
|
| 659 |
+
Now if you remember how asymmetric works in the world of asymmetric cryptography your public key is
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:08:47,000 --> 00:08:47,000
|
| 663 |
+
given to the world.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:08:47,000 --> 00:08:52,000
|
| 667 |
+
The question is how is Amazon distributing the public key to the rest of the world?
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:08:52,000 --> 00:08:54,000
|
| 671 |
+
Well, that's done using a certificate.
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:08:54,000 --> 00:08:58,000
|
| 675 |
+
So certificates are ways to pass the public key around.
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:08:58,000 --> 00:09:00,000
|
| 679 |
+
And that brings me to the SSL handshake.
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:09:00,000 --> 00:09:06,000
|
| 683 |
+
So exactly when I go to Amazon, what exactly happens in the background.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:09:06,000 --> 00:09:09,000
|
| 687 |
+
How am I getting this secure trust between them?
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:09:09,000 --> 00:09:15,000
|
| 691 |
+
How am I security transferring data and that brings me to the SSL handshake that I have right here.
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:09:15,000 --> 00:09:18,000
|
| 695 |
+
And again I took this from the IBM website.
|
| 696 |
+
|
| 697 |
+
175
|
| 698 |
+
00:09:19,000 --> 00:09:20,000
|
| 699 |
+
Uh.
|
| 700 |
+
|
| 701 |
+
176
|
| 702 |
+
00:09:20,000 --> 00:09:25,000
|
| 703 |
+
And the link is provided at the top of me.
|
| 704 |
+
|
| 705 |
+
177
|
| 706 |
+
00:09:25,000 --> 00:09:25,000
|
| 707 |
+
All right.
|
| 708 |
+
|
| 709 |
+
178
|
| 710 |
+
00:09:25,000 --> 00:09:26,000
|
| 711 |
+
Somewhere around there.
|
| 712 |
+
|
| 713 |
+
179
|
| 714 |
+
00:09:27,000 --> 00:09:28,000
|
| 715 |
+
Uh, so let's get into it.
|
| 716 |
+
|
| 717 |
+
180
|
| 718 |
+
00:09:28,000 --> 00:09:32,000
|
| 719 |
+
So now the steps are going to be listed on the left side of the screen.
|
| 720 |
+
|
| 721 |
+
181
|
| 722 |
+
00:09:32,000 --> 00:09:34,000
|
| 723 |
+
And I want to go over the diagram.
|
| 724 |
+
|
| 725 |
+
182
|
| 726 |
+
00:09:34,000 --> 00:09:40,000
|
| 727 |
+
So let's say in this diagram the client is you will put Andy.
|
| 728 |
+
|
| 729 |
+
183
|
| 730 |
+
00:09:42,000 --> 00:09:43,000
|
| 731 |
+
And the server is Amazon.
|
| 732 |
+
|
| 733 |
+
184
|
| 734 |
+
00:09:46,000 --> 00:09:50,000
|
| 735 |
+
Now I go to Amazon.com and I press enter.
|
| 736 |
+
|
| 737 |
+
185
|
| 738 |
+
00:09:50,000 --> 00:09:50,000
|
| 739 |
+
I type.
|
| 740 |
+
|
| 741 |
+
186
|
| 742 |
+
00:09:51,000 --> 00:09:51,000
|
| 743 |
+
Well, I don't go.
|
| 744 |
+
|
| 745 |
+
187
|
| 746 |
+
00:09:51,000 --> 00:09:54,000
|
| 747 |
+
I type Amazon.com and I press enter.
|
| 748 |
+
|
| 749 |
+
188
|
| 750 |
+
00:09:54,000 --> 00:09:55,000
|
| 751 |
+
What happens?
|
| 752 |
+
|
| 753 |
+
189
|
| 754 |
+
00:09:55,000 --> 00:09:58,000
|
| 755 |
+
The client issues a secure request session.
|
| 756 |
+
|
| 757 |
+
190
|
| 758 |
+
00:09:58,000 --> 00:10:03,000
|
| 759 |
+
So it's me going to Amazon and says, Hey Amazon, I need to set up a secure session with you.
|
| 760 |
+
|
| 761 |
+
191
|
| 762 |
+
00:10:03,000 --> 00:10:09,000
|
| 763 |
+
Amazon sends back an X509 certificate.
|
| 764 |
+
|
| 765 |
+
192
|
| 766 |
+
00:10:09,000 --> 00:10:11,000
|
| 767 |
+
That's the type of certificate that they're using.
|
| 768 |
+
|
| 769 |
+
193
|
| 770 |
+
00:10:11,000 --> 00:10:11,000
|
| 771 |
+
Now.
|
| 772 |
+
|
| 773 |
+
194
|
| 774 |
+
00:10:11,000 --> 00:10:14,000
|
| 775 |
+
In reality, almost all certificates are x509.
|
| 776 |
+
|
| 777 |
+
195
|
| 778 |
+
00:10:14,000 --> 00:10:16,000
|
| 779 |
+
They send back.
|
| 780 |
+
|
| 781 |
+
196
|
| 782 |
+
00:10:16,000 --> 00:10:21,000
|
| 783 |
+
The certificate that I showed you containing their public key.
|
| 784 |
+
|
| 785 |
+
197
|
| 786 |
+
00:10:21,000 --> 00:10:24,000
|
| 787 |
+
Now that we spoke about that, I showed you you.
|
| 788 |
+
|
| 789 |
+
198
|
| 790 |
+
00:10:24,000 --> 00:10:31,000
|
| 791 |
+
When you receive it, you're going to authenticate that certificate against a list of known certificate
|
| 792 |
+
|
| 793 |
+
199
|
| 794 |
+
00:10:31,000 --> 00:10:32,000
|
| 795 |
+
authorities.
|
| 796 |
+
|
| 797 |
+
200
|
| 798 |
+
00:10:32,000 --> 00:10:33,000
|
| 799 |
+
This is important.
|
| 800 |
+
|
| 801 |
+
201
|
| 802 |
+
00:10:33,000 --> 00:10:35,000
|
| 803 |
+
This is the part of the trust.
|
| 804 |
+
|
| 805 |
+
202
|
| 806 |
+
00:10:35,000 --> 00:10:39,000
|
| 807 |
+
So when you receive Amazon Cert, you're like, well, who gave him this cert?
|
| 808 |
+
|
| 809 |
+
203
|
| 810 |
+
00:10:39,000 --> 00:10:39,000
|
| 811 |
+
Okay.
|
| 812 |
+
|
| 813 |
+
204
|
| 814 |
+
00:10:39,000 --> 00:10:41,000
|
| 815 |
+
It was given by Digicert.
|
| 816 |
+
|
| 817 |
+
205
|
| 818 |
+
00:10:41,000 --> 00:10:45,000
|
| 819 |
+
Do you trust Digicert yes I do again your computer does all this.
|
| 820 |
+
|
| 821 |
+
206
|
| 822 |
+
00:10:45,000 --> 00:10:49,000
|
| 823 |
+
Your computer trusts Digicert now.
|
| 824 |
+
|
| 825 |
+
207
|
| 826 |
+
00:10:49,000 --> 00:10:50,000
|
| 827 |
+
What happened?
|
| 828 |
+
|
| 829 |
+
208
|
| 830 |
+
00:10:50,000 --> 00:10:57,000
|
| 831 |
+
You, the client on your computer, generate a symmetric key.
|
| 832 |
+
|
| 833 |
+
209
|
| 834 |
+
00:10:58,000 --> 00:11:05,000
|
| 835 |
+
Once you generate the symmetric key, you then encrypt it with the server's public key and you send
|
| 836 |
+
|
| 837 |
+
210
|
| 838 |
+
00:11:05,000 --> 00:11:06,000
|
| 839 |
+
it back.
|
| 840 |
+
|
| 841 |
+
211
|
| 842 |
+
00:11:06,000 --> 00:11:08,000
|
| 843 |
+
Notice the arrow to Amazon.
|
| 844 |
+
|
| 845 |
+
212
|
| 846 |
+
00:11:08,000 --> 00:11:09,000
|
| 847 |
+
So here's what you're doing.
|
| 848 |
+
|
| 849 |
+
213
|
| 850 |
+
00:11:09,000 --> 00:11:18,000
|
| 851 |
+
You're going to generate, for example, an AES 120 beta 128 bit or 256 bit AES key.
|
| 852 |
+
|
| 853 |
+
214
|
| 854 |
+
00:11:18,000 --> 00:11:21,000
|
| 855 |
+
You're then going to send it to Amazon.com.
|
| 856 |
+
|
| 857 |
+
215
|
| 858 |
+
00:11:21,000 --> 00:11:23,000
|
| 859 |
+
Amazon.
|
| 860 |
+
|
| 861 |
+
216
|
| 862 |
+
00:11:23,000 --> 00:11:27,000
|
| 863 |
+
Remember it was encrypted with their what public key.
|
| 864 |
+
|
| 865 |
+
217
|
| 866 |
+
00:11:27,000 --> 00:11:28,000
|
| 867 |
+
So what does Amazon do.
|
| 868 |
+
|
| 869 |
+
218
|
| 870 |
+
00:11:29,000 --> 00:11:32,000
|
| 871 |
+
Amazon once they receive.
|
| 872 |
+
|
| 873 |
+
219
|
| 874 |
+
00:11:33,000 --> 00:11:36,000
|
| 875 |
+
Uh, your symmetric key encrypted with their public key.
|
| 876 |
+
|
| 877 |
+
220
|
| 878 |
+
00:11:36,000 --> 00:11:38,000
|
| 879 |
+
They decrypt it with their corresponding.
|
| 880 |
+
|
| 881 |
+
221
|
| 882 |
+
00:11:38,000 --> 00:11:39,000
|
| 883 |
+
What?
|
| 884 |
+
|
| 885 |
+
222
|
| 886 |
+
00:11:39,000 --> 00:11:39,000
|
| 887 |
+
Private key.
|
| 888 |
+
|
| 889 |
+
223
|
| 890 |
+
00:11:39,000 --> 00:11:44,000
|
| 891 |
+
Remember, if you encrypt something with Amazon's public key, only Amazon's private key can decrypt
|
| 892 |
+
|
| 893 |
+
224
|
| 894 |
+
00:11:44,000 --> 00:11:44,000
|
| 895 |
+
it.
|
| 896 |
+
|
| 897 |
+
225
|
| 898 |
+
00:11:45,000 --> 00:11:52,000
|
| 899 |
+
Now Amazon has that public has that symmetric key or that session key that you make.
|
| 900 |
+
|
| 901 |
+
226
|
| 902 |
+
00:11:52,000 --> 00:11:55,000
|
| 903 |
+
Now the client and the server knows both.
|
| 904 |
+
|
| 905 |
+
227
|
| 906 |
+
00:11:55,000 --> 00:12:02,000
|
| 907 |
+
Now the client and server now both know that symmetric key and the what happens to the rest of it.
|
| 908 |
+
|
| 909 |
+
228
|
| 910 |
+
00:12:02,000 --> 00:12:10,000
|
| 911 |
+
Well you Amazon and you and Amazon will now use that symmetric key to encrypt data.
|
| 912 |
+
|
| 913 |
+
229
|
| 914 |
+
00:12:10,000 --> 00:12:11,000
|
| 915 |
+
So what happens is this.
|
| 916 |
+
|
| 917 |
+
230
|
| 918 |
+
00:12:12,000 --> 00:12:16,000
|
| 919 |
+
You generate a symmetric key, you encrypt it with Amazon's public key.
|
| 920 |
+
|
| 921 |
+
231
|
| 922 |
+
00:12:16,000 --> 00:12:19,000
|
| 923 |
+
Remember I showed you the actual public key there.
|
| 924 |
+
|
| 925 |
+
232
|
| 926 |
+
00:12:20,000 --> 00:12:22,000
|
| 927 |
+
You encrypt it with that public key.
|
| 928 |
+
|
| 929 |
+
233
|
| 930 |
+
00:12:22,000 --> 00:12:23,000
|
| 931 |
+
You send it to Amazon.
|
| 932 |
+
|
| 933 |
+
234
|
| 934 |
+
00:12:23,000 --> 00:12:25,000
|
| 935 |
+
Amazon then decrypts it with their private key.
|
| 936 |
+
|
| 937 |
+
235
|
| 938 |
+
00:12:26,000 --> 00:12:27,000
|
| 939 |
+
Now they have the symmetric key.
|
| 940 |
+
|
| 941 |
+
236
|
| 942 |
+
00:12:27,000 --> 00:12:28,000
|
| 943 |
+
You have the symmetric key.
|
| 944 |
+
|
| 945 |
+
237
|
| 946 |
+
00:12:28,000 --> 00:12:36,000
|
| 947 |
+
Anything that you send to Amazon username passwords credit cards address products you want to buy,
|
| 948 |
+
|
| 949 |
+
238
|
| 950 |
+
00:12:36,000 --> 00:12:39,000
|
| 951 |
+
search queries, anything that you want to send to Amazon.
|
| 952 |
+
|
| 953 |
+
239
|
| 954 |
+
00:12:39,000 --> 00:12:41,000
|
| 955 |
+
You encrypt it with that symmetric key.
|
| 956 |
+
|
| 957 |
+
240
|
| 958 |
+
00:12:41,000 --> 00:12:41,000
|
| 959 |
+
Send it to Amazon.
|
| 960 |
+
|
| 961 |
+
241
|
| 962 |
+
00:12:41,000 --> 00:12:43,000
|
| 963 |
+
Amazon already has the symmetric key.
|
| 964 |
+
|
| 965 |
+
242
|
| 966 |
+
00:12:44,000 --> 00:12:46,000
|
| 967 |
+
Amazon wants to send you back web pages.
|
| 968 |
+
|
| 969 |
+
243
|
| 970 |
+
00:12:46,000 --> 00:12:51,000
|
| 971 |
+
They want to send you back product listing confirmations and whatever they encrypt it with that symmetric
|
| 972 |
+
|
| 973 |
+
244
|
| 974 |
+
00:12:51,000 --> 00:12:51,000
|
| 975 |
+
key.
|
| 976 |
+
|
| 977 |
+
245
|
| 978 |
+
00:12:51,000 --> 00:12:56,000
|
| 979 |
+
Remember symmetric the same key used to encrypt is the same key used to decrypt.
|
| 980 |
+
|
| 981 |
+
246
|
| 982 |
+
00:12:56,000 --> 00:13:04,000
|
| 983 |
+
So all of this is happening in the background when you go and when when you go to Amazon and you purchase
|
| 984 |
+
|
| 985 |
+
247
|
| 986 |
+
00:13:04,000 --> 00:13:04,000
|
| 987 |
+
anything.
|
| 988 |
+
|
| 989 |
+
248
|
| 990 |
+
00:13:05,000 --> 00:13:05,000
|
| 991 |
+
All right.
|
| 992 |
+
|
| 993 |
+
249
|
| 994 |
+
00:13:05,000 --> 00:13:08,000
|
| 995 |
+
So that's something that you guys want to keep in mind as you use this.
|
| 996 |
+
|
| 997 |
+
250
|
| 998 |
+
00:13:08,000 --> 00:13:15,000
|
| 999 |
+
So if I go back here, if I go back to Amazon, all of what I just mentioned.
|
| 1000 |
+
|
| 1001 |
+
251
|
| 1002 |
+
00:13:16,000 --> 00:13:17,000
|
| 1003 |
+
Happens.
|
| 1004 |
+
|
| 1005 |
+
252
|
| 1006 |
+
00:13:17,000 --> 00:13:21,000
|
| 1007 |
+
So what if you go to another website?
|
| 1008 |
+
|
| 1009 |
+
253
|
| 1010 |
+
00:13:21,000 --> 00:13:21,000
|
| 1011 |
+
All right.
|
| 1012 |
+
|
| 1013 |
+
254
|
| 1014 |
+
00:13:21,000 --> 00:13:24,000
|
| 1015 |
+
What if you go to another, uh.
|
| 1016 |
+
|
| 1017 |
+
255
|
| 1018 |
+
00:13:26,000 --> 00:13:26,000
|
| 1019 |
+
Website?
|
| 1020 |
+
|
| 1021 |
+
256
|
| 1022 |
+
00:13:26,000 --> 00:13:27,000
|
| 1023 |
+
Google.com.
|
| 1024 |
+
|
| 1025 |
+
257
|
| 1026 |
+
00:13:27,000 --> 00:13:28,000
|
| 1027 |
+
Let's go to google.com.
|
| 1028 |
+
|
| 1029 |
+
258
|
| 1030 |
+
00:13:29,000 --> 00:13:31,000
|
| 1031 |
+
Google.com.
|
| 1032 |
+
|
| 1033 |
+
259
|
| 1034 |
+
00:13:31,000 --> 00:13:33,000
|
| 1035 |
+
Everything I just happened just happened.
|
| 1036 |
+
|
| 1037 |
+
260
|
| 1038 |
+
00:13:33,000 --> 00:13:35,000
|
| 1039 |
+
Everything I just went through just happened.
|
| 1040 |
+
|
| 1041 |
+
261
|
| 1042 |
+
00:13:35,000 --> 00:13:36,000
|
| 1043 |
+
So let's do a quick review.
|
| 1044 |
+
|
| 1045 |
+
262
|
| 1046 |
+
00:13:36,000 --> 00:13:37,000
|
| 1047 |
+
What happened?
|
| 1048 |
+
|
| 1049 |
+
263
|
| 1050 |
+
00:13:37,000 --> 00:13:40,000
|
| 1051 |
+
When I went to Google, I sent the request to Google.
|
| 1052 |
+
|
| 1053 |
+
264
|
| 1054 |
+
00:13:41,000 --> 00:13:43,000
|
| 1055 |
+
Google sent me back their certificate.
|
| 1056 |
+
|
| 1057 |
+
265
|
| 1058 |
+
00:13:43,000 --> 00:13:44,000
|
| 1059 |
+
Where is it?
|
| 1060 |
+
|
| 1061 |
+
266
|
| 1062 |
+
00:13:44,000 --> 00:13:49,000
|
| 1063 |
+
Well, if I click on the lock icon and I go to connection to secure and I say certificate, this is
|
| 1064 |
+
|
| 1065 |
+
267
|
| 1066 |
+
00:13:49,000 --> 00:13:50,000
|
| 1067 |
+
Google certificate.
|
| 1068 |
+
|
| 1069 |
+
268
|
| 1070 |
+
00:13:50,000 --> 00:13:55,000
|
| 1071 |
+
By acquiring Google certificate, I acquire Google's public key.
|
| 1072 |
+
|
| 1073 |
+
269
|
| 1074 |
+
00:13:56,000 --> 00:13:58,000
|
| 1075 |
+
This is the fingerprint if I go here.
|
| 1076 |
+
|
| 1077 |
+
270
|
| 1078 |
+
00:13:59,000 --> 00:14:00,000
|
| 1079 |
+
Whereas Google here we go.
|
| 1080 |
+
|
| 1081 |
+
271
|
| 1082 |
+
00:14:00,000 --> 00:14:01,000
|
| 1083 |
+
Google's public key.
|
| 1084 |
+
|
| 1085 |
+
272
|
| 1086 |
+
00:14:01,000 --> 00:14:03,000
|
| 1087 |
+
So I acquired a public key.
|
| 1088 |
+
|
| 1089 |
+
273
|
| 1090 |
+
00:14:03,000 --> 00:14:05,000
|
| 1091 |
+
What do I do with the public key?
|
| 1092 |
+
|
| 1093 |
+
274
|
| 1094 |
+
00:14:05,000 --> 00:14:08,000
|
| 1095 |
+
I generate a symmetric key on my computer.
|
| 1096 |
+
|
| 1097 |
+
275
|
| 1098 |
+
00:14:09,000 --> 00:14:15,000
|
| 1099 |
+
I then encrypt that symmetric key with Google's public key send it to Google.
|
| 1100 |
+
|
| 1101 |
+
276
|
| 1102 |
+
00:14:15,000 --> 00:14:17,000
|
| 1103 |
+
Google then decrypts it with their private key.
|
| 1104 |
+
|
| 1105 |
+
277
|
| 1106 |
+
00:14:17,000 --> 00:14:19,000
|
| 1107 |
+
Now they have the symmetric key.
|
| 1108 |
+
|
| 1109 |
+
278
|
| 1110 |
+
00:14:19,000 --> 00:14:20,000
|
| 1111 |
+
I have the symmetric key.
|
| 1112 |
+
|
| 1113 |
+
279
|
| 1114 |
+
00:14:20,000 --> 00:14:26,000
|
| 1115 |
+
What Google does is Google then encrypts the web page that I just saw on my screen and sends it to my
|
| 1116 |
+
|
| 1117 |
+
280
|
| 1118 |
+
00:14:26,000 --> 00:14:26,000
|
| 1119 |
+
machine.
|
| 1120 |
+
|
| 1121 |
+
281
|
| 1122 |
+
00:14:26,000 --> 00:14:31,000
|
| 1123 |
+
When my machine gets it, it decrypts it with symmetric key, all the search queries and all the pages
|
| 1124 |
+
|
| 1125 |
+
282
|
| 1126 |
+
00:14:31,000 --> 00:14:36,000
|
| 1127 |
+
that goes back and forth between me and Google is now encrypted with that symmetric key.
|
| 1128 |
+
|
| 1129 |
+
283
|
| 1130 |
+
00:14:36,000 --> 00:14:41,000
|
| 1131 |
+
What I just explained to you is the easiest way to understand SSL.
|
| 1132 |
+
|
| 1133 |
+
284
|
| 1134 |
+
00:14:41,000 --> 00:14:44,000
|
| 1135 |
+
This is the simplest explanation of it.
|
| 1136 |
+
|
| 1137 |
+
285
|
| 1138 |
+
00:14:44,000 --> 00:14:49,000
|
| 1139 |
+
Now it does get technical verification of signatures and all that, but you don't need to know that
|
| 1140 |
+
|
| 1141 |
+
286
|
| 1142 |
+
00:14:49,000 --> 00:14:50,000
|
| 1143 |
+
for your exam.
|
| 1144 |
+
|
| 1145 |
+
287
|
| 1146 |
+
00:14:50,000 --> 00:14:51,000
|
| 1147 |
+
Understand the SSL handshake.
|
| 1148 |
+
|
| 1149 |
+
288
|
| 1150 |
+
00:14:51,000 --> 00:14:55,000
|
| 1151 |
+
And now you see why it's so important to have certificates.
|
| 1152 |
+
|
| 1153 |
+
289
|
| 1154 |
+
00:14:55,000 --> 00:15:00,000
|
| 1155 |
+
Because without those certificates, the whole connection wouldn't be able to start.
|
| 1156 |
+
|
| 1157 |
+
290
|
| 1158 |
+
00:15:00,000 --> 00:15:01,000
|
| 1159 |
+
There'd be no way of passing that public key.
|
| 1160 |
+
|
| 1161 |
+
291
|
| 1162 |
+
00:15:01,000 --> 00:15:06,000
|
| 1163 |
+
There'll be no way to verify that that's Google's public key or Amazon's public key.
|
| 1164 |
+
|
| 1165 |
+
292
|
| 1166 |
+
00:15:06,000 --> 00:15:08,000
|
| 1167 |
+
But how do we get a certificate?
|
| 1168 |
+
|
| 1169 |
+
293
|
| 1170 |
+
00:15:08,000 --> 00:15:09,000
|
| 1171 |
+
How do we set this thing up?
|
| 1172 |
+
|
| 1173 |
+
294
|
| 1174 |
+
00:15:10,000 --> 00:15:12,000
|
| 1175 |
+
Well that we'll cover next.
|
| 1176 |
+
|
07 - Cryptography/017 PKI Process OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,664 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:00,000
|
| 3 |
+
Okay.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:00,000 --> 00:00:05,000
|
| 7 |
+
You have just been assigned the job of installing a certificate on a computer.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:05,000 --> 00:00:09,000
|
| 11 |
+
Your new your the new system administrator for a company.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:09,000 --> 00:00:13,000
|
| 15 |
+
And they said, well, we have a web server that we want to put a certificate on.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:13,000 --> 00:00:16,000
|
| 19 |
+
What is the process and exactly how is this done?
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:16,000 --> 00:00:21,000
|
| 23 |
+
So in this video I'm going to walk you guys through the process of how you can get a certificate, a
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:21,000 --> 00:00:24,000
|
| 27 |
+
trusted certificate on a computer.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:26,000
|
| 31 |
+
Let's get started in this one.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:26,000 --> 00:00:32,000
|
| 35 |
+
Now, in order to do this, there are basically four components that I need you to know for your exam.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:32,000 --> 00:00:37,000
|
| 39 |
+
When it comes to getting a certificate, the first thing is that digital certificate.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:37,000 --> 00:00:40,000
|
| 43 |
+
This is what you want to install on your computer.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:40,000 --> 00:00:42,000
|
| 47 |
+
If you remember I went over the SSL handshake.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:43,000 --> 00:00:48,000
|
| 51 |
+
And the SSL handshake begins with the passing of that digital certificate.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:48,000 --> 00:00:51,000
|
| 55 |
+
So this is a digital document that provides the public key.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:51,000 --> 00:00:55,000
|
| 59 |
+
It also has a digital signature that provides the trust to the organization.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:55,000 --> 00:00:58,000
|
| 63 |
+
Where are we going to get the certificates from?
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:58,000 --> 00:01:01,000
|
| 67 |
+
You're going to get that from a certificate authority.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:01,000 --> 00:01:07,000
|
| 71 |
+
This is a trusted entity that manages certificates and digitally signs the certificate.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:07,000 --> 00:01:08,000
|
| 75 |
+
This is the entity.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:08,000 --> 00:01:15,000
|
| 79 |
+
This is the DMV, I should say that verifies you are who you say you are.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:15,000 --> 00:01:23,000
|
| 83 |
+
Now, before the CA can give you a certificate, the CA needs to verify that you're you, that you're
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:23,000 --> 00:01:25,000
|
| 87 |
+
actually that company.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:25,000 --> 00:01:28,000
|
| 91 |
+
You're not trying to steal someone's identity, that you are Bob Jones.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:28,000 --> 00:01:30,000
|
| 95 |
+
That's the registration authority.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:30,000 --> 00:01:31,000
|
| 99 |
+
That's their job.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:31,000 --> 00:01:38,000
|
| 103 |
+
They're going to verify that the person is who they say they are for the CA before the CA can issue
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:38,000 --> 00:01:38,000
|
| 107 |
+
them a cert.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:38,000 --> 00:01:45,000
|
| 111 |
+
And when you start to give out your certificate on the internet, you're going to have to get it validated.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:45,000 --> 00:01:48,000
|
| 115 |
+
People that receive it is going to validate, hey, this certificate is still good.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:48,000 --> 00:01:51,000
|
| 119 |
+
It's kind of like me giving you my driver's license.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:51,000 --> 00:01:54,000
|
| 123 |
+
And you're like, well, I don't know.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:54,000 --> 00:01:57,000
|
| 127 |
+
It's this driver's license actually came from the DMV that's still valid.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:57,000 --> 00:02:02,000
|
| 131 |
+
So you call up a number to check if the license is valid.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:02,000 --> 00:02:04,000
|
| 135 |
+
That's the validation authority.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:04,000 --> 00:02:07,000
|
| 139 |
+
Now, I went to Wikipedia and I took their diagram.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:07,000 --> 00:02:10,000
|
| 143 |
+
I should say I borrowed it the diagram.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:10,000 --> 00:02:12,000
|
| 147 |
+
But I do have the link right here to it.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:12,000 --> 00:02:17,000
|
| 151 |
+
So here is the uh all of the information that we need.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:17,000 --> 00:02:21,000
|
| 155 |
+
Now I'm going to go through it, uh, at a high level right now.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:21,000 --> 00:02:25,000
|
| 159 |
+
And then we'll take a look at the slides in order to, to go more details into it.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:25,000 --> 00:02:29,000
|
| 163 |
+
So this is you right here.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:29,000 --> 00:02:29,000
|
| 167 |
+
This is you.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:29,000 --> 00:02:35,000
|
| 171 |
+
So the way you start this process is you what what you're going to do.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:35,000 --> 00:02:36,000
|
| 175 |
+
Let's put you on this.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:37,000 --> 00:02:42,000
|
| 179 |
+
What you're going to do is you're going to generate the public private key on your machine.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:42,000 --> 00:02:49,000
|
| 183 |
+
So you have a web server and you're going to create what's called a certificate request certificate,
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:49,000 --> 00:02:52,000
|
| 187 |
+
sign in requests or CSR on your machine.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:52,000 --> 00:02:56,000
|
| 191 |
+
What this does is that this is going to generate a public and a private key.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:57,000 --> 00:02:58,000
|
| 195 |
+
On your computer.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:58,000 --> 00:03:02,000
|
| 199 |
+
The certificate authority does not generate the public private keys.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:02,000 --> 00:03:04,000
|
| 203 |
+
It signs your public private key.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:04,000 --> 00:03:08,000
|
| 207 |
+
You generate that public private key pair on your machine.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:08,000 --> 00:03:09,000
|
| 211 |
+
So you generate.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:09,000 --> 00:03:12,000
|
| 215 |
+
This is going to be your private key.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:13,000 --> 00:03:15,000
|
| 219 |
+
And you generate your public key.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:15,000 --> 00:03:21,000
|
| 223 |
+
What you do now is you then take this and you submit it to a registration authority.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:21,000 --> 00:03:29,000
|
| 227 |
+
Now, the registration authority is the entity that verifies that you are who you say you are.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:29,000 --> 00:03:36,000
|
| 231 |
+
For example, let's say you are a hacker and you want to reproduce Amazon.com.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:36,000 --> 00:03:41,000
|
| 235 |
+
Well, you just can't go and get a certificate with the name Amazon.com because you're going to have
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:41,000 --> 00:03:43,000
|
| 239 |
+
to prove that you are Amazon.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:43,000 --> 00:03:50,000
|
| 243 |
+
If you are organization A or B or C, and you want to get a certificate for that organization, you're
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:50,000 --> 00:03:54,000
|
| 247 |
+
going to have to verify that you are that company and depend how it's done.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:54,000 --> 00:03:58,000
|
| 251 |
+
It may just be checking the domain actually belongs to you, or it may be that they're going to check
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:58,000 --> 00:04:00,000
|
| 255 |
+
that the company actually exists.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:00,000 --> 00:04:03,000
|
| 259 |
+
That's the registration authority.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:03,000 --> 00:04:06,000
|
| 263 |
+
So the registration authority stamps that OKC okay.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:06,000 --> 00:04:08,000
|
| 267 |
+
This is Bob.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:08,000 --> 00:04:10,000
|
| 271 |
+
This is company A this is what.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:10,000 --> 00:04:12,000
|
| 275 |
+
And you can trust them.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:12,000 --> 00:04:16,000
|
| 279 |
+
The registration authority then sends your public key.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:16,000 --> 00:04:17,000
|
| 283 |
+
To the CA.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:17,000 --> 00:04:26,000
|
| 287 |
+
The CA then takes all of your company information, all this great stuff that was given to them, including
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:26,000 --> 00:04:32,000
|
| 291 |
+
your public key and what the CA does is it then sends you back a certificate.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:32,000 --> 00:04:39,000
|
| 295 |
+
Now on the certificate it contains your public key, but it also contains a digital signature from the
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:39,000 --> 00:04:39,000
|
| 299 |
+
CA.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:40,000 --> 00:04:45,000
|
| 303 |
+
Now if you remember what a digital signature is, a digital signature verifies that something actually
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:45,000 --> 00:04:48,000
|
| 307 |
+
came from that entity and it was never modified.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:48,000 --> 00:04:58,000
|
| 311 |
+
So when you receive this certificate and you install it on your web server, this certificate was never
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:58,000 --> 00:05:00,000
|
| 315 |
+
actually issued by you, was it?
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:05:00,000 --> 00:05:01,000
|
| 319 |
+
It came from who?
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:05:01,000 --> 00:05:02,000
|
| 323 |
+
The certificate authority.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:05:02,000 --> 00:05:06,000
|
| 327 |
+
The only thing it has that you really gave it was basically a public key.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:05:06,000 --> 00:05:08,000
|
| 331 |
+
But the certificate has more information.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:08,000 --> 00:05:12,000
|
| 335 |
+
I have a video coming up later on all the other data that the certificate contains.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:12,000 --> 00:05:18,000
|
| 339 |
+
So what you do is you install that certificate on your machine.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:18,000 --> 00:05:20,000
|
| 343 |
+
Now you're done with these entities.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:20,000 --> 00:05:27,000
|
| 347 |
+
Now somebody comes to Shop.com or whatever your website is, and the first thing you're going to do,
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:27,000 --> 00:05:32,000
|
| 351 |
+
if you remember the SSL handshake is you're going to do what you're going to send them that certificate
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:32,000 --> 00:05:35,000
|
| 355 |
+
so you can start the SSL connection.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:35,000 --> 00:05:36,000
|
| 359 |
+
You send them the certificate.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:36,000 --> 00:05:38,000
|
| 363 |
+
Well, how do they know the certificate is still valid?
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:38,000 --> 00:05:42,000
|
| 367 |
+
How do they know your website hasn't been hacked or something went wrong?
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:42,000 --> 00:05:47,000
|
| 371 |
+
You didn't renew the certificate, you became malicious and your company is stealing data now.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:48,000 --> 00:05:52,000
|
| 375 |
+
Well, what they do is they send their certificate to a validation authority.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:52,000 --> 00:05:57,000
|
| 379 |
+
Now notice the CA also sent information to the validation authority.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:57,000 --> 00:05:59,000
|
| 383 |
+
To day I issue this cert.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:59,000 --> 00:06:05,000
|
| 387 |
+
And if anybody ever wants to check if it's good just let them know it's okay because we did issue that.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:06:06,000 --> 00:06:12,000
|
| 391 |
+
The validation authority when they when the user gets it, checks it and says okay it's good.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:06:12,000 --> 00:06:14,000
|
| 395 |
+
Tells back to use a yeah, this is good.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:06:14,000 --> 00:06:14,000
|
| 399 |
+
You can use it.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:06:14,000 --> 00:06:17,000
|
| 403 |
+
And this starts the entire SSL connection.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:06:18,000 --> 00:06:24,000
|
| 407 |
+
So this is the PKI process in a nutshell with a CA, an RA and a VA.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:06:24,000 --> 00:06:33,000
|
| 411 |
+
Now I just want to point out something that even though in this particular diagram it looks like it's
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:33,000 --> 00:06:34,000
|
| 415 |
+
different entities.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:34,000 --> 00:06:37,000
|
| 419 |
+
RA it's all the same entity.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:37,000 --> 00:06:39,000
|
| 423 |
+
Generally this like Digicert.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:40,000 --> 00:06:44,000
|
| 427 |
+
Uh, GoDaddy or whoever you're using as your public key.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:44,000 --> 00:06:45,000
|
| 431 |
+
It's always the same entity.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:45,000 --> 00:06:48,000
|
| 435 |
+
It's not going to be like it's three different businesses.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:48,000 --> 00:06:56,000
|
| 439 |
+
But in organizations that utilizes internal certs, they can have different machines to do this particular
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:56,000 --> 00:06:57,000
|
| 443 |
+
job.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:57,000 --> 00:07:00,000
|
| 447 |
+
Now let's take a look at some things here.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:07:00,000 --> 00:07:04,000
|
| 451 |
+
Now everything I covered is in detail on these two sections.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:07:04,000 --> 00:07:06,000
|
| 455 |
+
So I'm going to go over them quickly since we covered it already.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:07:06,000 --> 00:07:09,000
|
| 459 |
+
So the certificate signing request.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:07:09,000 --> 00:07:13,000
|
| 463 |
+
So this is the part of it where we had to.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:07:14,000 --> 00:07:15,000
|
| 467 |
+
Obtain.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:15,000 --> 00:07:19,000
|
| 471 |
+
This is the request we're going to send to the CA to get that digital certificate.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:19,000 --> 00:07:19,000
|
| 475 |
+
All right.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:07:19,000 --> 00:07:24,000
|
| 479 |
+
So the first thing we're going to be doing is in order to do this, we're going to have to include things
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:07:24,000 --> 00:07:29,000
|
| 483 |
+
like our organization name, our domain name, what country we're in, and of course our public key.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:07:29,000 --> 00:07:31,000
|
| 487 |
+
So this is what we're sending.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:31,000 --> 00:07:35,000
|
| 491 |
+
Now the first thing you want to do is you want to start this process.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:35,000 --> 00:07:41,000
|
| 495 |
+
When you want to get a certificate is you have to go to your machine and you have to create a key pair,
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:41,000 --> 00:07:43,000
|
| 499 |
+
that public private key pair.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:43,000 --> 00:07:44,000
|
| 503 |
+
Remember the private key is kept secret.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:44,000 --> 00:07:46,000
|
| 507 |
+
The public key is given to anyone.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:46,000 --> 00:07:48,000
|
| 511 |
+
You want to fill in the details.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:48,000 --> 00:07:49,000
|
| 515 |
+
All right.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:49,000 --> 00:07:52,000
|
| 519 |
+
The certificate is going to have a is going to need a lot of information.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:52,000 --> 00:07:55,000
|
| 523 |
+
All this information the name of your company where it's located state.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:55,000 --> 00:07:58,000
|
| 527 |
+
And I'm going to show you certificate details in the next video.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:58,000 --> 00:08:01,000
|
| 531 |
+
And you're going to see a certificate has all this information.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:08:02,000 --> 00:08:08,000
|
| 535 |
+
So you create this, uh, you create it using a software.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:08:08,000 --> 00:08:14,000
|
| 539 |
+
And this is going to be submitted in a format that the CAS can understand that format.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:08:14,000 --> 00:08:18,000
|
| 543 |
+
But I get into technical is called PK, CS number ten.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:08:18,000 --> 00:08:21,000
|
| 547 |
+
This is the format that it's submitted into.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:08:21,000 --> 00:08:27,000
|
| 551 |
+
This is just a file format, if you think about it like an Excel file as dot xls x.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:08:27,000 --> 00:08:28,000
|
| 555 |
+
That's the file format.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:08:28,000 --> 00:08:29,000
|
| 559 |
+
This is just the file format.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:08:29,000 --> 00:08:30,000
|
| 563 |
+
What does it contain?
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:08:30,000 --> 00:08:33,000
|
| 567 |
+
Well, the public key and all the corresponding information.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:08:34,000 --> 00:08:38,000
|
| 571 |
+
Now you submit the CSR to the RA to the CA.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:08:38,000 --> 00:08:39,000
|
| 575 |
+
What happens here?
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:08:40,000 --> 00:08:43,000
|
| 579 |
+
Uh, they will validate your identity.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:08:43,000 --> 00:08:44,000
|
| 583 |
+
They'll validate that you're good.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:08:45,000 --> 00:08:50,000
|
| 587 |
+
And once they can validate all that information, we'll talk more about validations coming up a little
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:08:50,000 --> 00:08:51,000
|
| 591 |
+
bit later.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:08:51,000 --> 00:08:53,000
|
| 595 |
+
But they're going to validate that you're good.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:08:53,000 --> 00:08:58,000
|
| 599 |
+
Sometimes they may validate your just your domain name or sometimes they'll do an extended validation.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:08:58,000 --> 00:09:03,000
|
| 603 |
+
We're going to do more than a domain name that you actually own that domain, but you actually own that
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:09:03,000 --> 00:09:04,000
|
| 607 |
+
business.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:09:04,000 --> 00:09:06,000
|
| 611 |
+
Then the certificate is issued to you.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:09:06,000 --> 00:09:12,000
|
| 615 |
+
You install it on your web server, and you're ready to rock and roll with the SSL connection.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:09:12,000 --> 00:09:12,000
|
| 619 |
+
Okay.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:09:12,000 --> 00:09:16,000
|
| 623 |
+
So that's the process of how to get a certificate.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:09:17,000 --> 00:09:24,000
|
| 627 |
+
Now I want you guys to keep in mind that this is a very easy and simple process.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:09:24,000 --> 00:09:28,000
|
| 631 |
+
It's if you've ever installed a certificate on a web server, it's a very simple thing.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:09:28,000 --> 00:09:33,000
|
| 635 |
+
You go to the web server, you do a few clicks that give you doing an IIs server, and you create that
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:09:33,000 --> 00:09:34,000
|
| 639 |
+
certificate request.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:09:34,000 --> 00:09:38,000
|
| 643 |
+
You go to your CA, you basically install it there and they give you a certificate.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:09:38,000 --> 00:09:39,000
|
| 647 |
+
You put it back on your web server.
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:09:39,000 --> 00:09:44,000
|
| 651 |
+
There's something that's done actually doesn't take very long, a few minutes if you know the skills
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:09:44,000 --> 00:09:44,000
|
| 655 |
+
to do it.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:09:44,000 --> 00:09:46,000
|
| 659 |
+
So it's not complex to do.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:09:46,000 --> 00:09:50,000
|
| 663 |
+
But for your exam you want to be able to understand the process, which is what we just went over.
|
| 664 |
+
|
07 - Cryptography/018 Certificates OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,824 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:02,000
|
| 3 |
+
In this video we're going to be talking about certificates.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:02,000 --> 00:00:05,000
|
| 7 |
+
What exactly is on a certificate?
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:05,000 --> 00:00:07,000
|
| 11 |
+
Now, I already went over that.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:07,000 --> 00:00:11,000
|
| 15 |
+
It has the signature from the, uh, certificate authority.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:12,000 --> 00:00:13,000
|
| 19 |
+
It also has your public key.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:13,000 --> 00:00:14,000
|
| 23 |
+
But what else does it contain?
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:14,000 --> 00:00:16,000
|
| 27 |
+
Let's get into that.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:16,000 --> 00:00:17,000
|
| 31 |
+
I want to talk about the format.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:17,000 --> 00:00:20,000
|
| 35 |
+
Self-signed certificates versus third party certificates.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:20,000 --> 00:00:21,000
|
| 39 |
+
Let's knock it out.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:21,000 --> 00:00:26,000
|
| 43 |
+
The first thing I want to do is I want to show you guys when you have a certificate.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:27,000 --> 00:00:29,000
|
| 47 |
+
Now, a certificate has a variety of different fields.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:29,000 --> 00:00:31,000
|
| 51 |
+
It's not just the couple things.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:31,000 --> 00:00:35,000
|
| 55 |
+
In fact, it has a couple different things on it, from a version number to the subject's name, the
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:35,000 --> 00:00:38,000
|
| 59 |
+
company's name, your public key.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:38,000 --> 00:00:43,000
|
| 63 |
+
Who gave you the certificate, how long it's valid for, what digital signature algorithm you're using,
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:43,000 --> 00:00:47,000
|
| 67 |
+
and a unique serial number to identify the certificate.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:47,000 --> 00:00:48,000
|
| 71 |
+
You know the certificate types.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:48,000 --> 00:00:53,000
|
| 75 |
+
Now, I do want to mention this, that all certificates that are coming out today is going to be the
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:00:53,000 --> 00:00:55,000
|
| 79 |
+
X509 certificate.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:00:55,000 --> 00:00:57,000
|
| 83 |
+
It's going to be a certificate format.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:00:57,000 --> 00:01:02,000
|
| 87 |
+
Now the certificate types are going to be either it's going to be self-signed or it's going to be third
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:02,000 --> 00:01:04,000
|
| 91 |
+
party issue, which we'll take a look at in a few minutes.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:04,000 --> 00:01:14,000
|
| 95 |
+
So I want to show you all of these fields on an actual certificate so you can better understand what
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:14,000 --> 00:01:14,000
|
| 99 |
+
I'm talking about.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:14,000 --> 00:01:16,000
|
| 103 |
+
So let's go to Amazon.com.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:16,000 --> 00:01:17,000
|
| 107 |
+
Here we are back again.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:18,000 --> 00:01:19,000
|
| 111 |
+
Connection is secure.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:19,000 --> 00:01:22,000
|
| 115 |
+
Let's take a look at some of the things I mentioned.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:22,000 --> 00:01:23,000
|
| 119 |
+
So we're going to go to detail.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:23,000 --> 00:01:25,000
|
| 123 |
+
So we have all the data.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:25,000 --> 00:01:29,000
|
| 127 |
+
So right now I'm just going to expand some of these boxes so you can see them.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:30,000 --> 00:01:32,000
|
| 131 |
+
Uh first of all what version is it.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:32,000 --> 00:01:34,000
|
| 135 |
+
Well this is version three certificate.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:34,000 --> 00:01:35,000
|
| 139 |
+
Here is a serial number.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:35,000 --> 00:01:38,000
|
| 143 |
+
Now this is a unique number that is unique to this certificate.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:38,000 --> 00:01:40,000
|
| 147 |
+
No certificate should have this.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:01:40,000 --> 00:01:42,000
|
| 151 |
+
The signature algorithm.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:01:43,000 --> 00:01:49,000
|
| 155 |
+
Now, I mentioned that a digital signature using the DSS standards is generally some kind of asymmetric
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:01:49,000 --> 00:01:51,000
|
| 159 |
+
algorithm and a hashing algorithm.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:01:51,000 --> 00:01:56,000
|
| 163 |
+
In this one, we're going to be using Sha 256 with RSA.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:01:56,000 --> 00:01:58,000
|
| 167 |
+
Pretty pretty standard.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:01:58,000 --> 00:02:00,000
|
| 171 |
+
Who gave us the certificate.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:00,000 --> 00:02:04,000
|
| 175 |
+
Now Digicert is one of the biggest provider of certificate.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:04,000 --> 00:02:08,000
|
| 179 |
+
Digicert took over from Symantec's who took over VeriSign.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:08,000 --> 00:02:11,000
|
| 183 |
+
VeriSign being one of the most popular names out there.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:11,000 --> 00:02:16,000
|
| 187 |
+
But Digicert is now them, and there's a lot of big names in this space.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:16,000 --> 00:02:17,000
|
| 191 |
+
Uh, such as?
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:18,000 --> 00:02:23,000
|
| 195 |
+
I know GoDaddy gives out a lot of certificates, you can get Google search and so on.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:23,000 --> 00:02:24,000
|
| 199 |
+
How long is it valid?
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:24,000 --> 00:02:24,000
|
| 203 |
+
What?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:24,000 --> 00:02:26,000
|
| 207 |
+
A certificate is not valid forever.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:26,000 --> 00:02:31,000
|
| 211 |
+
In fact, you have to renew certificates generally every 1 to 3 years.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:31,000 --> 00:02:41,000
|
| 215 |
+
You notice, uh, this particular certificate is valid basically from 1127 23 to 11 1124.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:41,000 --> 00:02:46,000
|
| 219 |
+
So this is about a one year, a little less than a one year certificate.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:02:46,000 --> 00:02:54,000
|
| 223 |
+
The subject, well, the chronological or the key name, this certificate is only for WW dot amazon.com.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:02:54,000 --> 00:02:58,000
|
| 227 |
+
So this is certificate can only be used at WW dot.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:02:58,000 --> 00:03:01,000
|
| 231 |
+
So this is going to be a certificate only for this website.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:01,000 --> 00:03:03,000
|
| 235 |
+
But who exactly.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:04,000 --> 00:03:05,000
|
| 239 |
+
I'm.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:05,000 --> 00:03:06,000
|
| 243 |
+
So where is the public key on this.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:06,000 --> 00:03:08,000
|
| 247 |
+
So the subject's public key.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:08,000 --> 00:03:09,000
|
| 251 |
+
So we have.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:10,000 --> 00:03:12,000
|
| 255 |
+
The the public key algorithm.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:12,000 --> 00:03:13,000
|
| 259 |
+
It's an RSA key.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:13,000 --> 00:03:15,000
|
| 263 |
+
Here is the public key.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:15,000 --> 00:03:19,000
|
| 267 |
+
Now in here there are some additional things I don't.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:19,000 --> 00:03:23,000
|
| 271 |
+
You don't need to go into all of these things such as certificate policies and all that.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:23,000 --> 00:03:29,000
|
| 275 |
+
But what I do need you guys to know is there is something we call a CRL distribution point, certificate
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:29,000 --> 00:03:35,000
|
| 279 |
+
revocation list distribution point, which you can find on the certificate itself to check if the certificate
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:35,000 --> 00:03:37,000
|
| 283 |
+
has been revoked.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:37,000 --> 00:03:40,000
|
| 287 |
+
That is something we're going to cover a little bit later.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:03:41,000 --> 00:03:45,000
|
| 291 |
+
If I just take a look at the general part of the certificate, you can see it's just giving me some
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:03:45,000 --> 00:03:50,000
|
| 295 |
+
of the basic information that I had their start on expires on.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:03:50,000 --> 00:03:57,000
|
| 299 |
+
So this is going to be some of the main fields that you should understand about a certificate.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:03:58,000 --> 00:04:02,000
|
| 303 |
+
Now when you get a certificate let's go back to slides here.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:02,000 --> 00:04:03,000
|
| 307 |
+
Oops.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:04,000 --> 00:04:05,000
|
| 311 |
+
Uh, there's a couple of things here.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:06,000 --> 00:04:12,000
|
| 315 |
+
When you get a certificate, there's what's called an entity certificate, what's called a domain validation
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:12,000 --> 00:04:14,000
|
| 319 |
+
certificate and extended validation.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:14,000 --> 00:04:20,000
|
| 323 |
+
When you go out and you purchase a certificate from somebody like Digicert, a domain validation just
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:20,000 --> 00:04:26,000
|
| 327 |
+
checks if you actually own the domain Amazon.com, but it doesn't verify if that business is associated
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:26,000 --> 00:04:27,000
|
| 331 |
+
with that domain.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:27,000 --> 00:04:30,000
|
| 335 |
+
That's going to be called an extended validation.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:30,000 --> 00:04:36,000
|
| 339 |
+
Sometimes if you go to a website and the the bar at the top turns green, that's an extended validation
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:36,000 --> 00:04:37,000
|
| 343 |
+
certificate.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:37,000 --> 00:04:41,000
|
| 347 |
+
Another type of certificate you can get is what's called a wild card certificate.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:41,000 --> 00:04:44,000
|
| 351 |
+
So wild card certificates if you notice it has a wild card.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:44,000 --> 00:04:49,000
|
| 355 |
+
If you remember the one on Amazon was just WW dot amazon.com.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:50,000 --> 00:04:53,000
|
| 359 |
+
That can't be used for anything but that w w dot.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:04:53,000 --> 00:04:59,000
|
| 363 |
+
If you go and you get a wildcard certificate with a wildcard, you notice how I have this wildcard at
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:04:59,000 --> 00:05:00,000
|
| 367 |
+
Tidcombe.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:00,000 --> 00:05:05,000
|
| 371 |
+
So we could use it for t w w dot t edu comm.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:05,000 --> 00:05:07,000
|
| 375 |
+
You can use it for mail at tidcombe.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:07,000 --> 00:05:13,000
|
| 379 |
+
We can use it maybe for if you had a subdomain called vpn at t com ftp at tidcombe.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:13,000 --> 00:05:17,000
|
| 383 |
+
So you can use it for multiple subdomains.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:17,000 --> 00:05:26,000
|
| 387 |
+
Now I do want to talk about when you get a certificate, you can get them either from yourself or you
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:26,000 --> 00:05:29,000
|
| 391 |
+
can get them from a certificate authority like Digicert.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:30,000 --> 00:05:34,000
|
| 395 |
+
And there are many, like I said, Digicert GoDaddy.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:34,000 --> 00:05:37,000
|
| 399 |
+
I use a site called cheap SSL.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:37,000 --> 00:05:40,000
|
| 403 |
+
Uh, so there is a ton of them.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:40,000 --> 00:05:42,000
|
| 407 |
+
I'm not going to get into all the different names.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:42,000 --> 00:05:43,000
|
| 411 |
+
It's out of the scope here.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:43,000 --> 00:05:49,000
|
| 415 |
+
But if you just go to Google and you type, uh, SSL certificates or purchase certificates, you know
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:49,000 --> 00:05:51,000
|
| 419 |
+
what I'll do that when I get here so I can show you some of the names here.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:51,000 --> 00:05:52,000
|
| 423 |
+
Okay.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:52,000 --> 00:05:53,000
|
| 427 |
+
But let's go.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:53,000 --> 00:05:59,000
|
| 431 |
+
Self-signed certificates A self-signed certificate is a certificate that you make internally in your
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:59,000 --> 00:06:01,000
|
| 435 |
+
organization.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:01,000 --> 00:06:05,000
|
| 439 |
+
The problem with a self-signed certificate is the trust level.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:05,000 --> 00:06:10,000
|
| 443 |
+
Okay, so this is something that you make internally, and it has no independence of trust.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:10,000 --> 00:06:12,000
|
| 447 |
+
In other words, only you trust it.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:12,000 --> 00:06:15,000
|
| 451 |
+
Only your organization trusts it.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:15,000 --> 00:06:18,000
|
| 455 |
+
Now, you're probably saying yourself, well, is it useful?
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:18,000 --> 00:06:27,000
|
| 459 |
+
Well, it's it's useful as much, externally speaking, as an ID that you make inside.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:28,000 --> 00:06:28,000
|
| 463 |
+
Okay.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:28,000 --> 00:06:28,000
|
| 467 |
+
Think about this.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:28,000 --> 00:06:34,000
|
| 471 |
+
If you are a company and you create badges for all your employees.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:35,000 --> 00:06:41,000
|
| 475 |
+
Those employees can't use your company badges or IDs to externally validate anything externally.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:41,000 --> 00:06:44,000
|
| 479 |
+
They can't give it to highway patrol and says, this is me, right?
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:44,000 --> 00:06:48,000
|
| 483 |
+
Nobody's going to know what kind of stupid ID is this?
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:48,000 --> 00:06:49,000
|
| 487 |
+
We don't trust this.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:06:49,000 --> 00:06:52,000
|
| 491 |
+
But people in your organization will.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:06:52,000 --> 00:07:02,000
|
| 495 |
+
So if you want to set up SSL connection within your organization, that is okay because it's all trusted
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:02,000 --> 00:07:04,000
|
| 499 |
+
internally, but you need that SSL connection.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:04,000 --> 00:07:07,000
|
| 503 |
+
Then I recommend a self-signed certificate.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:07,000 --> 00:07:08,000
|
| 507 |
+
The cost is free.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:08,000 --> 00:07:09,000
|
| 511 |
+
That's what makes it good.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:09,000 --> 00:07:13,000
|
| 515 |
+
It's actually free versus Digicert can cost a couple GS a year.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:14,000 --> 00:07:15,000
|
| 519 |
+
A couple of thousand dollars.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:15,000 --> 00:07:19,000
|
| 523 |
+
So the use case here is going to be for internal networks applications.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:19,000 --> 00:07:26,000
|
| 527 |
+
If you need to issue certificates for smart cards, people log in internal SSL on web servers, internally
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:26,000 --> 00:07:29,000
|
| 531 |
+
speaking, where it never touches the external world.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:30,000 --> 00:07:32,000
|
| 535 |
+
This is a good solution.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:32,000 --> 00:07:35,000
|
| 539 |
+
It's free and you should be doing this.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:35,000 --> 00:07:36,000
|
| 543 |
+
I.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:07:36,000 --> 00:07:41,000
|
| 547 |
+
In fact at TI we have a ton of self-signed certificates on all of our internal servers now.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:07:42,000 --> 00:07:48,000
|
| 551 |
+
If what you're doing is going to be external facing and you need that external validation, you need
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:07:48,000 --> 00:07:56,000
|
| 555 |
+
that DMV, I should say to validate your request, then you can go and get a third party certificate.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:07:56,000 --> 00:07:58,000
|
| 559 |
+
And before I get into this, you know what?
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:07:58,000 --> 00:08:00,000
|
| 563 |
+
Let me just show it to you.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:08:01,000 --> 00:08:02,000
|
| 567 |
+
Uh, all the different.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:08:04,000 --> 00:08:09,000
|
| 571 |
+
So I'm going to go to Google and I am going to say.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:08:11,000 --> 00:08:12,000
|
| 575 |
+
Where is my, uh.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:08:12,000 --> 00:08:12,000
|
| 579 |
+
Here we go.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:08:12,000 --> 00:08:12,000
|
| 583 |
+
Oh.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:08:12,000 --> 00:08:13,000
|
| 587 |
+
Let's stop.
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:08:13,000 --> 00:08:13,000
|
| 591 |
+
Here we go.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:08:13,000 --> 00:08:20,000
|
| 595 |
+
So I'm going to go to Google, and here we go with all kinds of certificates.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:08:20,000 --> 00:08:22,000
|
| 599 |
+
All these names here are going to start popping up.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:08:23,000 --> 00:08:30,000
|
| 603 |
+
Uh, and notice I have uh, Comodo certificates are popular, GoDaddy certificates are popular.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:08:30,000 --> 00:08:32,000
|
| 607 |
+
There's one that says cheap SSL.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:08:32,000 --> 00:08:34,000
|
| 611 |
+
I use this one on a private web server.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:08:36,000 --> 00:08:38,000
|
| 615 |
+
Uh, you can get them from Digicert.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:08:38,000 --> 00:08:43,000
|
| 619 |
+
GoDaddy and Digicert is going to be your big player in the game.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:08:43,000 --> 00:08:48,000
|
| 623 |
+
So if you want a certificate, this is going to be where you're going to get the the biggest, uh,
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:08:48,000 --> 00:08:56,000
|
| 627 |
+
certificates from like the highest name I would say comes from Digicert, but Digicert certificates
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:08:56,000 --> 00:08:57,000
|
| 631 |
+
are not cheap.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:08:58,000 --> 00:09:03,000
|
| 635 |
+
They're pretty expensive and they do have extended validation certificates and so on.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:09:03,000 --> 00:09:03,000
|
| 639 |
+
Okay.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:09:03,000 --> 00:09:05,000
|
| 643 |
+
So you guys can check that if you want a certificate.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:09:05,000 --> 00:09:10,000
|
| 647 |
+
There's tons of certificate external parties that you can get a third party cert from.
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:09:10,000 --> 00:09:13,000
|
| 651 |
+
But the question is why would you want a third party cert.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:09:13,000 --> 00:09:16,000
|
| 655 |
+
And the reason is a third party certificate.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:09:16,000 --> 00:09:19,000
|
| 659 |
+
It's all about trust.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:09:19,000 --> 00:09:27,000
|
| 663 |
+
You see, the difference between a self-signed certificate and a third party certificate is just here.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:09:27,000 --> 00:09:30,000
|
| 667 |
+
It's not the level of encryption strength.
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:09:30,000 --> 00:09:31,000
|
| 671 |
+
It's just a trust.
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:09:31,000 --> 00:09:40,000
|
| 675 |
+
For example, let's say I create an ID in my house that has my name, my picture, my wait, no, my
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:09:40,000 --> 00:09:43,000
|
| 679 |
+
height and my eye color and my address.
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:09:43,000 --> 00:09:49,000
|
| 683 |
+
It has the exact same information as my driver's license.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:09:49,000 --> 00:09:55,000
|
| 687 |
+
Then what is the difference between my ID and internal ID and the driver's license?
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:09:56,000 --> 00:09:59,000
|
| 691 |
+
Nothing except the trust.
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:09:59,000 --> 00:10:04,000
|
| 695 |
+
People are more likely to trust the DMV stamp than they are to trust me, saying I'm me.
|
| 696 |
+
|
| 697 |
+
175
|
| 698 |
+
00:10:04,000 --> 00:10:05,000
|
| 699 |
+
That is the only difference.
|
| 700 |
+
|
| 701 |
+
176
|
| 702 |
+
00:10:05,000 --> 00:10:10,000
|
| 703 |
+
So when you get a third party certificate, you're not going to get any more IT security.
|
| 704 |
+
|
| 705 |
+
177
|
| 706 |
+
00:10:10,000 --> 00:10:12,000
|
| 707 |
+
I'm going to get a higher level encryption, for example.
|
| 708 |
+
|
| 709 |
+
178
|
| 710 |
+
00:10:12,000 --> 00:10:19,000
|
| 711 |
+
In fact, if you generate an internally, you can select to use bigger RSA keys, or you can select
|
| 712 |
+
|
| 713 |
+
179
|
| 714 |
+
00:10:19,000 --> 00:10:23,000
|
| 715 |
+
a type of uh, RSA key or the type of hashing you want to use.
|
| 716 |
+
|
| 717 |
+
180
|
| 718 |
+
00:10:23,000 --> 00:10:25,000
|
| 719 |
+
So you can actually even make it more secure.
|
| 720 |
+
|
| 721 |
+
181
|
| 722 |
+
00:10:25,000 --> 00:10:32,000
|
| 723 |
+
For example, if I internally, if I put the weight on my ID versus the DMV doesn't have that, then
|
| 724 |
+
|
| 725 |
+
182
|
| 726 |
+
00:10:32,000 --> 00:10:39,000
|
| 727 |
+
technically my internal ID has more unique identifying factors than the DMV does, but the DMV comes
|
| 728 |
+
|
| 729 |
+
183
|
| 730 |
+
00:10:39,000 --> 00:10:40,000
|
| 731 |
+
with that trust factor.
|
| 732 |
+
|
| 733 |
+
184
|
| 734 |
+
00:10:41,000 --> 00:10:41,000
|
| 735 |
+
All right.
|
| 736 |
+
|
| 737 |
+
185
|
| 738 |
+
00:10:41,000 --> 00:10:42,000
|
| 739 |
+
This trust factor.
|
| 740 |
+
|
| 741 |
+
186
|
| 742 |
+
00:10:42,000 --> 00:10:49,000
|
| 743 |
+
So the CA the external CA like Digicert they're going to give you that certificate.
|
| 744 |
+
|
| 745 |
+
187
|
| 746 |
+
00:10:49,000 --> 00:10:54,000
|
| 747 |
+
They're going to sign digitally signed with a digital signature on the certificate to verify that it
|
| 748 |
+
|
| 749 |
+
188
|
| 750 |
+
00:10:54,000 --> 00:10:55,000
|
| 751 |
+
came from them.
|
| 752 |
+
|
| 753 |
+
189
|
| 754 |
+
00:10:56,000 --> 00:10:57,000
|
| 755 |
+
This is going to be.
|
| 756 |
+
|
| 757 |
+
190
|
| 758 |
+
00:10:57,000 --> 00:11:00,000
|
| 759 |
+
The trust is most central to most secure communication.
|
| 760 |
+
|
| 761 |
+
191
|
| 762 |
+
00:11:00,000 --> 00:11:02,000
|
| 763 |
+
If you're doing Https, where are you going to use this?
|
| 764 |
+
|
| 765 |
+
192
|
| 766 |
+
00:11:02,000 --> 00:11:07,000
|
| 767 |
+
You should be using third party certificates for anything that is public facing websites.
|
| 768 |
+
|
| 769 |
+
193
|
| 770 |
+
00:11:07,000 --> 00:11:11,000
|
| 771 |
+
Anything that faces the public that public users come to.
|
| 772 |
+
|
| 773 |
+
194
|
| 774 |
+
00:11:11,000 --> 00:11:12,000
|
| 775 |
+
The cost?
|
| 776 |
+
|
| 777 |
+
195
|
| 778 |
+
00:11:12,000 --> 00:11:14,000
|
| 779 |
+
It will be a cost and it can vary.
|
| 780 |
+
|
| 781 |
+
196
|
| 782 |
+
00:11:14,000 --> 00:11:18,000
|
| 783 |
+
You can get a certificate for a few bucks a year to a few thousand dollars a year, depending on the
|
| 784 |
+
|
| 785 |
+
197
|
| 786 |
+
00:11:18,000 --> 00:11:19,000
|
| 787 |
+
entity.
|
| 788 |
+
|
| 789 |
+
198
|
| 790 |
+
00:11:19,000 --> 00:11:24,000
|
| 791 |
+
I'm not going to get into the exact why it depends on warranty and how much you trust them, and if
|
| 792 |
+
|
| 793 |
+
199
|
| 794 |
+
00:11:24,000 --> 00:11:27,000
|
| 795 |
+
they can get hacked and how secure they are.
|
| 796 |
+
|
| 797 |
+
200
|
| 798 |
+
00:11:28,000 --> 00:11:29,000
|
| 799 |
+
I'm not going to get into all that.
|
| 800 |
+
|
| 801 |
+
201
|
| 802 |
+
00:11:29,000 --> 00:11:30,000
|
| 803 |
+
It's not needed for your course, but it does.
|
| 804 |
+
|
| 805 |
+
202
|
| 806 |
+
00:11:30,000 --> 00:11:32,000
|
| 807 |
+
There is a cost associated with this.
|
| 808 |
+
|
| 809 |
+
203
|
| 810 |
+
00:11:33,000 --> 00:11:35,000
|
| 811 |
+
Bottom line goes like this.
|
| 812 |
+
|
| 813 |
+
204
|
| 814 |
+
00:11:35,000 --> 00:11:42,000
|
| 815 |
+
If you're going to get a certificate for internal access, and you will never have any kind of external
|
| 816 |
+
|
| 817 |
+
205
|
| 818 |
+
00:11:42,000 --> 00:11:49,000
|
| 819 |
+
access into that machine, self-signed certificates may be just fine, but if any external access is
|
| 820 |
+
|
| 821 |
+
206
|
| 822 |
+
00:11:49,000 --> 00:11:56,000
|
| 823 |
+
required to that machine, for example, like a public website, make sure to get a third party certificate.
|
| 824 |
+
|
07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,220 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:00,000
|
| 3 |
+
Okay.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:00,000 --> 00:00:06,000
|
| 7 |
+
When you're building a PKI, especially internally, you're going to want to understand how the structure
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:06,000 --> 00:00:08,000
|
| 11 |
+
of the PKI is laid out.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:08,000 --> 00:00:14,000
|
| 15 |
+
So in this video, we want to take a look at that particular structure, uh, of a PKI.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:14,000 --> 00:00:18,000
|
| 19 |
+
Now, this this topic in particular is called the root of trust.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:18,000 --> 00:00:20,000
|
| 23 |
+
And it's how the PKI are managed.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:20,000 --> 00:00:21,000
|
| 27 |
+
It's basically how you structure it.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:22,000 --> 00:00:27,000
|
| 31 |
+
So when you set up a PKI, you have a root CA.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:27,000 --> 00:00:30,000
|
| 35 |
+
Underneath that you have what's called subordinate CAS.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:30,000 --> 00:00:30,000
|
| 39 |
+
All right.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:30,000 --> 00:00:32,000
|
| 43 |
+
Now why do we have this?
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:32,000 --> 00:00:34,000
|
| 47 |
+
Well you see this root CA.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:34,000 --> 00:00:37,000
|
| 51 |
+
This root CA technically doesn't issue certificates.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:37,000 --> 00:00:39,000
|
| 55 |
+
Let's go back to the process of getting a certificate.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:39,000 --> 00:00:44,000
|
| 59 |
+
If you remember in that process the CA digitally signs your certificate.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:45,000 --> 00:00:52,000
|
| 63 |
+
If you remember how a digital signature works is that the CA utilizes its private key, it hashes all
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:52,000 --> 00:00:53,000
|
| 67 |
+
the information on your.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:53,000 --> 00:00:58,000
|
| 71 |
+
The way it's done is that it will hash all the information on a certificate to company.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:58,000 --> 00:01:04,000
|
| 75 |
+
Name your domain name, uh, the certificate start and end dates.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:04,000 --> 00:01:10,000
|
| 79 |
+
It then hashes all this information and then it encrypts it with its private key.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:10,000 --> 00:01:11,000
|
| 83 |
+
Remember how signatures are done.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:12,000 --> 00:01:18,000
|
| 87 |
+
So if that certificate like for example, let's say Digicert.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:18,000 --> 00:01:19,000
|
| 91 |
+
If Digicert.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:20,000 --> 00:01:26,000
|
| 95 |
+
Ever gets compromised and their private key is compromised.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:26,000 --> 00:01:33,000
|
| 99 |
+
Every single certificate, the millions and millions of certificate that Digicert has ever given out,
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:33,000 --> 00:01:35,000
|
| 103 |
+
becomes invalid instantly.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:35,000 --> 00:01:38,000
|
| 107 |
+
Because then anybody could remake the certificate because they have the private key.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:38,000 --> 00:01:40,000
|
| 111 |
+
And of course, everybody had the public key.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:40,000 --> 00:01:41,000
|
| 115 |
+
It was always public.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:41,000 --> 00:01:51,000
|
| 119 |
+
So in order to help minimize this kind of impact, what we do is we set up a root CA and then subordinate
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:51,000 --> 00:01:51,000
|
| 123 |
+
CAS.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:51,000 --> 00:01:55,000
|
| 127 |
+
Now the reason why you have this is because of this.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:55,000 --> 00:01:57,000
|
| 131 |
+
You you set up a root CA.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:58,000 --> 00:02:05,000
|
| 135 |
+
And this root CA will then issue a certificate to the subordinate CAS which can then issue it to even
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:05,000 --> 00:02:06,000
|
| 139 |
+
lower CAS.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:06,000 --> 00:02:11,000
|
| 143 |
+
The reason you do this is because then you can take the root CA offline when I mean offline.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:11,000 --> 00:02:17,000
|
| 147 |
+
This is a computer that is literally unplugged, shut off, and put into a vault a couple thousand feet
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:17,000 --> 00:02:23,000
|
| 151 |
+
in the air because this is certify and this and this is certifying this.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:23,000 --> 00:02:31,000
|
| 155 |
+
So technically speaking, if somebody hacks the company and they hack this lower CA right here at the
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:31,000 --> 00:02:34,000
|
| 159 |
+
bottom, then you know what?
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:34,000 --> 00:02:39,000
|
| 163 |
+
All the certificate that's issued by this cert by DCA is invalidated.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:39,000 --> 00:02:42,000
|
| 167 |
+
Not everything in the entire organization.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:42,000 --> 00:02:48,000
|
| 171 |
+
So what this does is this helps to minimize the impact of the data breach or the attack.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:48,000 --> 00:02:49,000
|
| 175 |
+
That's what you would want.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:49,000 --> 00:02:55,000
|
| 179 |
+
This you don't you never want to just start issuing certificate from your root CA because if that root
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:55,000 --> 00:02:56,000
|
| 183 |
+
CA.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:57,000 --> 00:02:58,000
|
| 187 |
+
Is.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:59,000 --> 00:03:03,000
|
| 191 |
+
If that route C is ever compromised, every search you've ever given is invalidated.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:03,000 --> 00:03:06,000
|
| 195 |
+
But if you branch it off into four subordinates.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:07,000 --> 00:03:11,000
|
| 199 |
+
Then if one of those is compromised, there's just those certs are compromised, not the other three.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:11,000 --> 00:03:16,000
|
| 203 |
+
So that's why you would want to use this kind of structure.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:16,000 --> 00:03:19,000
|
| 207 |
+
Now this kind of structure is only done well.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:19,000 --> 00:03:20,000
|
| 211 |
+
It's done basically for two reasons.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:20,000 --> 00:03:25,000
|
| 215 |
+
Number one easier to administer and of course for the data protection.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:25,000 --> 00:03:29,000
|
| 219 |
+
That way if something happens, not everything becomes invalidated.
|
| 220 |
+
|
07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,372 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:00,000
|
| 3 |
+
Okay.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:00,000 --> 00:00:05,000
|
| 7 |
+
When you receive a certificate from someone, you have to verify that it actually came from them.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:05,000 --> 00:00:11,000
|
| 11 |
+
There's a couple of things here that we need to know for our exam when it comes to this process of verification.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:11,000 --> 00:00:14,000
|
| 15 |
+
And again, this is when a user wants to validate your certificate.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:14,000 --> 00:00:19,000
|
| 19 |
+
So somebody comes to an app, maybe like a web app that you made or a device that you're using.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:19,000 --> 00:00:23,000
|
| 23 |
+
Maybe you have certificates installed on your on your firewall for VPN and so on.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:23,000 --> 00:00:25,000
|
| 27 |
+
Somebody comes there and they get a certificate.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:25,000 --> 00:00:27,000
|
| 31 |
+
They want to verify that it's coming from you.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:27,000 --> 00:00:31,000
|
| 35 |
+
If I get into that, do I want to talk about a firm that you may see appear on your exam?
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:31,000 --> 00:00:32,000
|
| 39 |
+
It's called certificate pinning.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:32,000 --> 00:00:35,000
|
| 43 |
+
This is a techniques that helps to prevent man in the middle attacks.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:35,000 --> 00:00:39,000
|
| 47 |
+
What it does is that it hard codes the SSL public key into an app.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:40,000 --> 00:00:44,000
|
| 51 |
+
This means that when the output device communicates with the server to compare the SSL certificates
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:44,000 --> 00:00:46,000
|
| 55 |
+
public key with the one in the app.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:46,000 --> 00:00:48,000
|
| 59 |
+
Now let me give you an example how this works.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:48,000 --> 00:00:48,000
|
| 63 |
+
So.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:49,000 --> 00:00:54,000
|
| 67 |
+
Let's say you have an application, and every time people come, they get your certificate and then
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:54,000 --> 00:00:55,000
|
| 71 |
+
they check the certificate.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:55,000 --> 00:01:00,000
|
| 75 |
+
Now, what you can do in order to prevent people from intercepting or changing anything, you can hardcode
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:00,000 --> 00:01:02,000
|
| 79 |
+
the public key in the application itself.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:02,000 --> 00:01:07,000
|
| 83 |
+
So then the certificate that's given to them by the SSL process, they can then compare it to the application's
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:07,000 --> 00:01:08,000
|
| 87 |
+
public key.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:08,000 --> 00:01:16,000
|
| 91 |
+
That way no one can intercept the certificate or change it and say that this is their certificate of
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:16,000 --> 00:01:19,000
|
| 95 |
+
any kind, because you have a hardcoded the public key in the app.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:20,000 --> 00:01:21,000
|
| 99 |
+
Okay.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:21,000 --> 00:01:24,000
|
| 103 |
+
Let's move on here quickly to the verification process.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:24,000 --> 00:01:28,000
|
| 107 |
+
So when you get a certificate all right a couple of things here.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:28,000 --> 00:01:33,000
|
| 111 |
+
The certificate verification process includes verifying the digital signature of the CA is authentic.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:33,000 --> 00:01:35,000
|
| 115 |
+
And they trust the CA.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:35,000 --> 00:01:39,000
|
| 119 |
+
So when you receive a certificate you're going to check okay.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:39,000 --> 00:01:41,000
|
| 123 |
+
Who the certificate came from.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:41,000 --> 00:01:42,000
|
| 127 |
+
Digicert.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:42,000 --> 00:01:49,000
|
| 131 |
+
I want you guys to keep in mind that your computer has a list of already pre-approved certificate authorities
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:49,000 --> 00:01:50,000
|
| 135 |
+
that it trusts.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:50,000 --> 00:01:55,000
|
| 139 |
+
You're then going to check that a signature on it to make sure it's good.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:56,000 --> 00:02:02,000
|
| 143 |
+
One of the things that you guys will check is what's called a CRL, the certificate revocation list.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:02,000 --> 00:02:06,000
|
| 147 |
+
This is a published list of certificates that have been revoked.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:06,000 --> 00:02:08,000
|
| 151 |
+
Let's talk about this revocation process.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:08,000 --> 00:02:16,000
|
| 155 |
+
Sometimes when you get a certificate, you yourself may want to revoke the certificate for reasons such
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:16,000 --> 00:02:19,000
|
| 159 |
+
as you're changing the server and the server is not valid anymore.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:19,000 --> 00:02:23,000
|
| 163 |
+
The server crashed, your server was hacked, and you lost the private key.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:23,000 --> 00:02:27,000
|
| 167 |
+
Something happened internally and you don't want to use that certificate anymore.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:27,000 --> 00:02:33,000
|
| 171 |
+
So you call your certificate provider like Digicert and say, well, can you reissue this cert?
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:33,000 --> 00:02:34,000
|
| 175 |
+
Desert we have is no good.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:35,000 --> 00:02:37,000
|
| 179 |
+
So maybe your server got hacked.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:37,000 --> 00:02:40,000
|
| 183 |
+
So you call Digicert and say, well, my server got hacked.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:40,000 --> 00:02:42,000
|
| 187 |
+
I need a brand new certificate.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:42,000 --> 00:02:43,000
|
| 191 |
+
So Digicert says, no problem.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:43,000 --> 00:02:48,000
|
| 195 |
+
Here's a brand new certificate with a and you generate a new public private key pair.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:48,000 --> 00:02:50,000
|
| 199 |
+
Now what happens to that old certificate?
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:50,000 --> 00:02:53,000
|
| 203 |
+
You see the old certificate that Digicert issued?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:53,000 --> 00:02:56,000
|
| 207 |
+
It's still technically valid.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:56,000 --> 00:02:56,000
|
| 211 |
+
Here's why.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:56,000 --> 00:03:00,000
|
| 215 |
+
Because the public the the expiration date hasn't occurred yet.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:00,000 --> 00:03:01,000
|
| 219 |
+
So it's not expired.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:02,000 --> 00:03:04,000
|
| 223 |
+
The signature is still valid.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:04,000 --> 00:03:10,000
|
| 227 |
+
Remember, signature is the hash of the certificate encrypted with the CA's private key.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:11,000 --> 00:03:13,000
|
| 231 |
+
That's still valid.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:13,000 --> 00:03:16,000
|
| 235 |
+
So anybody that receives that certificate is going to think it's valid.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:16,000 --> 00:03:24,000
|
| 239 |
+
So what we do is we will publish a list of certificates that's revoked.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:24,000 --> 00:03:27,000
|
| 243 |
+
So when people come to the website, they're going to check the CRL list.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:27,000 --> 00:03:32,000
|
| 247 |
+
Or they check this thing called Ocsp, an online certificate status protocol.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:32,000 --> 00:03:35,000
|
| 251 |
+
This is a real time validation with the CA.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:35,000 --> 00:03:36,000
|
| 255 |
+
This is a is this valid?
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:36,000 --> 00:03:37,000
|
| 259 |
+
The CA is like yeah that's good.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:38,000 --> 00:03:43,000
|
| 263 |
+
Now the certificate usually contains the data that you're going to be trusting such as that public key.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:43,000 --> 00:03:46,000
|
| 267 |
+
So this is the revocation that I was mentioning.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:46,000 --> 00:03:51,000
|
| 271 |
+
So when it's compromised it gets added to the certificate revocation list.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:51,000 --> 00:03:57,000
|
| 275 |
+
If you want a real time validation that the certificate is actually good.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:57,000 --> 00:04:00,000
|
| 279 |
+
Then you use all CSP.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:00,000 --> 00:04:01,000
|
| 283 |
+
Know that for your exam.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:01,000 --> 00:04:02,000
|
| 287 |
+
There's a real time.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:02,000 --> 00:04:07,000
|
| 291 |
+
So right now, almost all of us, every time we go to Amazon or we get the certificate, we use this
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:07,000 --> 00:04:10,000
|
| 295 |
+
protocol to check if that certificate is still valid.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:11,000 --> 00:04:15,000
|
| 299 |
+
Another time you may see on your exam is something we call certificate stapling.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:15,000 --> 00:04:16,000
|
| 303 |
+
All right.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:16,000 --> 00:04:20,000
|
| 307 |
+
And what this does is that it avoids the client from sending the Ocsp request.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:20,000 --> 00:04:27,000
|
| 311 |
+
Instead, the web server itself checks the validation with the CA now certificate stapling is this.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:27,000 --> 00:04:34,000
|
| 315 |
+
Every time you get, uh, the certificate, you have to check with the ocsp.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:34,000 --> 00:04:35,000
|
| 319 |
+
Is it good?
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:35,000 --> 00:04:35,000
|
| 323 |
+
Okay, great.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:35,000 --> 00:04:36,000
|
| 327 |
+
Let me use it.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:36,000 --> 00:04:44,000
|
| 331 |
+
How about if I just the actual web server gets the validation, and then when you receive the certificate,
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:44,000 --> 00:04:48,000
|
| 335 |
+
you're receiving the validation that you're looking for and the certificate.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:48,000 --> 00:04:48,000
|
| 339 |
+
So that's what this does.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:48,000 --> 00:04:51,000
|
| 343 |
+
It makes it a lot easier so you don't have to waste time.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:51,000 --> 00:04:52,000
|
| 347 |
+
Keep going here.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:53,000 --> 00:04:54,000
|
| 351 |
+
Okay.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:54,000 --> 00:04:56,000
|
| 355 |
+
Revocation is a is a pretty important thing.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:56,000 --> 00:05:01,000
|
| 359 |
+
At some point, if in your history of managing web servers or managing this kind of technology like
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:01,000 --> 00:05:06,000
|
| 363 |
+
SSL, you're probably going to have to revoke a cert when a cert is revoked.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:06,000 --> 00:05:11,000
|
| 367 |
+
It has to be a way for other users in the public internet, or in turn, your organization to note that
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:11,000 --> 00:05:15,000
|
| 371 |
+
certificate is no good and these are the ways that it's done.
|
| 372 |
+
|
07 - Cryptography/021 Steganography OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,392 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
Okay, let's talk of a pretty cool technology called steganography.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:11,000
|
| 7 |
+
Now, steganography is basically a technique where you're able to encode a hidden message into different
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:11,000 --> 00:00:17,000
|
| 11 |
+
things, such as pictures, audio files, video files, or text files.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:17,000 --> 00:00:20,000
|
| 15 |
+
And I have a link here that I want you guys to try.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:20,000 --> 00:00:25,000
|
| 19 |
+
I'm going to show you guys how to use that, and I'm going to show you guys how we can take an image
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:25,000 --> 00:00:27,000
|
| 23 |
+
and encode a secret message into it.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:27,000 --> 00:00:31,000
|
| 27 |
+
Why is this bad and somewhat good?
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:31,000 --> 00:00:38,000
|
| 31 |
+
So let's say you're working in an organization and you are a bad person, and you want to get secret
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:38,000 --> 00:00:44,000
|
| 35 |
+
data out of that organization right in front of their faces, and they would never know.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:44,000 --> 00:00:46,000
|
| 39 |
+
So here's what you do.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:46,000 --> 00:00:51,000
|
| 43 |
+
You go to the office and you take a group picture with all your bosses and everyone, and then you take
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:51,000 --> 00:00:53,000
|
| 47 |
+
that picture and you put it on your computer.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:53,000 --> 00:01:00,000
|
| 51 |
+
What you do then is you take the company's secret information, secret data, and you encode it into
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:01:00,000 --> 00:01:00,000
|
| 55 |
+
the picture.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:01,000 --> 00:01:07,000
|
| 59 |
+
Then what you do is you email the picture out outside to your personal private email.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:07,000 --> 00:01:12,000
|
| 63 |
+
And then what happens is when you get home, you decode the picture and you take the message out the
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:12,000 --> 00:01:13,000
|
| 67 |
+
picture.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:13,000 --> 00:01:19,000
|
| 71 |
+
So this picture is flying around the internet, but the picture is actually just a front for the secret
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:19,000 --> 00:01:21,000
|
| 75 |
+
message that lies behind it.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:21,000 --> 00:01:24,000
|
| 79 |
+
It's actually really easy to do, and you can even do a website that does it.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:24,000 --> 00:01:26,000
|
| 83 |
+
And I'll show you guys how easy it is.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:26,000 --> 00:01:31,000
|
| 87 |
+
Now, what I'm describing to you here is called image steganography.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:31,000 --> 00:01:37,000
|
| 91 |
+
And this what they do is they modify LSB the least significant bit in the image.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:37,000 --> 00:01:42,000
|
| 95 |
+
Basically, they're going to modify the image to the point where the human eyes can notice that the
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:42,000 --> 00:01:44,000
|
| 99 |
+
image has actually been modified.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:44,000 --> 00:01:50,000
|
| 103 |
+
You could also do this with audio file concealing the information within audio files, or particularly
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:50,000 --> 00:01:54,000
|
| 107 |
+
all kinds of video files like MP4 video files are famous for this.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:54,000 --> 00:01:59,000
|
| 111 |
+
You can even embed it into white spaces into certain text document.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:59,000 --> 00:02:06,000
|
| 115 |
+
Now for this I want to show you guys how it's done, and I'll give you guys some ways of how to detect
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:06,000 --> 00:02:06,000
|
| 119 |
+
it.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:06,000 --> 00:02:07,000
|
| 123 |
+
So let's take a look here.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:07,000 --> 00:02:11,000
|
| 127 |
+
Here I am at that particular website that I just showed you.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:11,000 --> 00:02:14,000
|
| 131 |
+
Now on my desktop.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:14,000 --> 00:02:15,000
|
| 135 |
+
Let me pull up my desktop here.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:17,000 --> 00:02:19,000
|
| 139 |
+
On my desktop, I have an image.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:21,000 --> 00:02:24,000
|
| 143 |
+
I have this image that I just downloaded, royalty free image.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:24,000 --> 00:02:26,000
|
| 147 |
+
And let's see what it looks like.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:26,000 --> 00:02:28,000
|
| 151 |
+
This image of a laptop that I have.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:28,000 --> 00:02:33,000
|
| 155 |
+
So what I'm going to do is I'm going to encode select file.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:33,000 --> 00:02:34,000
|
| 159 |
+
I'm going to choose my image.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:36,000 --> 00:02:37,000
|
| 163 |
+
There is my desktop.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:37,000 --> 00:02:38,000
|
| 167 |
+
Here we go.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:38,000 --> 00:02:39,000
|
| 171 |
+
Image image image.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:39,000 --> 00:02:47,000
|
| 175 |
+
So I select the image and I'm going to put a message that says Andrew has many certifications.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:47,000 --> 00:02:48,000
|
| 179 |
+
That's my message.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:48,000 --> 00:02:50,000
|
| 183 |
+
And this is your original image.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:50,000 --> 00:02:53,000
|
| 187 |
+
Now you're not going to notice a difference when it encodes it.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:54,000 --> 00:02:55,000
|
| 191 |
+
Okay.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:55,000 --> 00:03:00,000
|
| 195 |
+
So here's the binary representation of the actual image that it's that it's encoding it into.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:00,000 --> 00:03:05,000
|
| 199 |
+
And here is the actual stick node image.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:06,000 --> 00:03:07,000
|
| 203 |
+
It says message hidden in the image.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:07,000 --> 00:03:10,000
|
| 207 |
+
You can't tell the difference between that and this.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:11,000 --> 00:03:16,000
|
| 211 |
+
Now, when you try it on your computer, try to see the human eyes cannot tell.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:16,000 --> 00:03:19,000
|
| 215 |
+
Now what I'm going to do is I'm going to right click and I'm going to save this one.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:21,000 --> 00:03:24,000
|
| 219 |
+
And uh, we're going to call it now, I already tried this.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:24,000 --> 00:03:27,000
|
| 223 |
+
I wanted to try it before it before showing to you.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:27,000 --> 00:03:34,000
|
| 227 |
+
So we're going to call S I stick node image for now dot png.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:34,000 --> 00:03:34,000
|
| 231 |
+
All right.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:34,000 --> 00:03:36,000
|
| 235 |
+
So we're going to save this.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:37,000 --> 00:03:38,000
|
| 239 |
+
All right, that's it.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:38,000 --> 00:03:39,000
|
| 243 |
+
It's saved.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:39,000 --> 00:03:43,000
|
| 247 |
+
Now, if I open up the image, you notice it pretty much is the same thing.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:43,000 --> 00:03:49,000
|
| 251 |
+
Now, let's say I can give this image to a lot of people around the internet.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:49,000 --> 00:03:53,000
|
| 255 |
+
Uh, no one would know unless you actually know there is an image.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:53,000 --> 00:03:55,000
|
| 259 |
+
So let's close out this site.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:55,000 --> 00:03:57,000
|
| 263 |
+
I'm going to reopen it.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:59,000 --> 00:04:00,000
|
| 267 |
+
So you can see it's all brand new.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:00,000 --> 00:04:02,000
|
| 271 |
+
So I'm going to go to decode this time.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:02,000 --> 00:04:04,000
|
| 275 |
+
I'm going to select the file.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:05,000 --> 00:04:07,000
|
| 279 |
+
Including the downloads folder.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:07,000 --> 00:04:07,000
|
| 283 |
+
We had it.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:08,000 --> 00:04:09,000
|
| 287 |
+
Here we go.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:10,000 --> 00:04:12,000
|
| 291 |
+
So this is the image the input I'm just going to click on decode.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:13,000 --> 00:04:15,000
|
| 295 |
+
And notice my message has just popped up.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:16,000 --> 00:04:18,000
|
| 299 |
+
You can see the message right there at the top.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:19,000 --> 00:04:19,000
|
| 303 |
+
All right.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:19,000 --> 00:04:20,000
|
| 307 |
+
Very good.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:20,000 --> 00:04:22,000
|
| 311 |
+
So that is steganography.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:22,000 --> 00:04:29,000
|
| 315 |
+
Steganography is just the way of embedding a message into an image, or a text file, or a movie file
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:29,000 --> 00:04:29,000
|
| 319 |
+
or audio file.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:29,000 --> 00:04:35,000
|
| 323 |
+
Now, the way you can tell is the file size.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:35,000 --> 00:04:35,000
|
| 327 |
+
All right.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:35,000 --> 00:04:40,000
|
| 331 |
+
The way you can tell if an image has signal, you would need to have that original file.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:40,000 --> 00:04:46,000
|
| 335 |
+
And if you believe that an image has some kind of steganography behind it, look at the file size.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:46,000 --> 00:04:49,000
|
| 339 |
+
Another thing you can do is run it against a hash checker.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:49,000 --> 00:04:53,000
|
| 343 |
+
The hash of the images would be different because one of them just has more information than the other.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:53,000 --> 00:04:55,000
|
| 347 |
+
There are some ways of checking.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:55,000 --> 00:04:58,000
|
| 351 |
+
Other than that, there's not many different ways of stopping this thing.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:58,000 --> 00:05:04,000
|
| 355 |
+
Steganography is difficult to detect, but it's as difficult to detect.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:05,000 --> 00:05:14,000
|
| 359 |
+
But this is why you should limit the output in or send in of things like, uh, images and audio files
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:14,000 --> 00:05:15,000
|
| 363 |
+
outside your organization.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:15,000 --> 00:05:20,000
|
| 367 |
+
Because now that you know that this exists, maybe you shouldn't allow images to go out.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:20,000 --> 00:05:25,000
|
| 371 |
+
In fact, one of the dumbest things I see organizations do sometimes.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:25,000 --> 00:05:32,000
|
| 375 |
+
I got an email from a bank, like legitimate email from a representative of a bank, and in it they
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:32,000 --> 00:05:35,000
|
| 379 |
+
have the logo of the bank and the email signature of the person.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:35,000 --> 00:05:42,000
|
| 383 |
+
That's smart, because if the head of the bank realizes that they can embed messages into that little
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:42,000 --> 00:05:44,000
|
| 387 |
+
logo, I don't think they would have allowed it.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:44,000 --> 00:05:49,000
|
| 391 |
+
So it's important to know what this thing is and realize it's difficult to detect.
|
| 392 |
+
|
07 - Cryptography/022 Blockchain OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,476 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:03,000
|
| 3 |
+
In this video, we're going to talk of a pretty famous technology.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:03,000 --> 00:00:06,000
|
| 7 |
+
And that technology is called blockchain.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:06,000 --> 00:00:09,000
|
| 11 |
+
Now blockchain I'm going to show you guys how a blockchain is built.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:09,000 --> 00:00:15,000
|
| 15 |
+
But this particular technology is famous in cryptocurrencies where most people hears it from.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:15,000 --> 00:00:21,000
|
| 19 |
+
But blockchain can be applied to many different applications, whether it's an accounting application,
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:21,000 --> 00:00:24,000
|
| 23 |
+
banking transactions or all different kinds of financial transactions.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:24,000 --> 00:00:25,000
|
| 27 |
+
You can use a blockchain.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:25,000 --> 00:00:27,000
|
| 31 |
+
So it's not just for cryptocurrency.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:27,000 --> 00:00:30,000
|
| 35 |
+
In fact, this video has nothing to do with cryptocurrency.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:30,000 --> 00:00:31,000
|
| 39 |
+
Let's get started.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:31,000 --> 00:00:38,000
|
| 43 |
+
So blockchain let's take a look at some definitions before I show you exactly how a blockchain is built.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:38,000 --> 00:00:46,000
|
| 47 |
+
So a blockchain is known as a decentralized and distributed ledger technology known for its role in
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:46,000 --> 00:00:47,000
|
| 51 |
+
underpinning cryptocurrency.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:47,000 --> 00:00:53,000
|
| 55 |
+
Like I mentioned now a blockchain is just a chain of blocks where each block represents a list of transaction.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:53,000 --> 00:00:58,000
|
| 59 |
+
Each transaction in the blockchain is secured through a cryptographic principle known as hashing, which
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:58,000 --> 00:01:00,000
|
| 63 |
+
we covered earlier in the course.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:00,000 --> 00:01:05,000
|
| 67 |
+
The blockchain is decentralized and maintain across a network of computers across all of the nodes in
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:05,000 --> 00:01:07,000
|
| 71 |
+
that particular system.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:07,000 --> 00:01:10,000
|
| 75 |
+
It does utilize a hash function.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:10,000 --> 00:01:15,000
|
| 79 |
+
Each block contains a cryptographic hash of the previous block, chaining them together.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:15,000 --> 00:01:17,000
|
| 83 |
+
This ensures that each block is added to.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:17,000 --> 00:01:21,000
|
| 87 |
+
Jim cannot be altered without messing up all the blocks that comes after it.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:22,000 --> 00:01:24,000
|
| 91 |
+
Lots of information here.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:24,000 --> 00:01:27,000
|
| 95 |
+
Let me show you it and it'll make more sense.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:27,000 --> 00:01:29,000
|
| 99 |
+
So I have an image.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:30,000 --> 00:01:33,000
|
| 103 |
+
Uh, from Money.com.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:33,000 --> 00:01:38,000
|
| 107 |
+
And I want to show you guys what is, you know, what exactly is how how a blockchain works.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:38,000 --> 00:01:43,000
|
| 111 |
+
So first of all, when they say the word decentralized ledger, let's take the word ledger.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:43,000 --> 00:01:48,000
|
| 115 |
+
Ledger literally means list when they say a list of transactions.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:48,000 --> 00:01:54,000
|
| 119 |
+
When you design a blockchain, you design how many of these transactions are going to be stored on every
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:54,000 --> 00:01:55,000
|
| 123 |
+
single block.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:55,000 --> 00:01:58,000
|
| 127 |
+
So every block can hold a list of transactions.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:58,000 --> 00:02:02,000
|
| 131 |
+
Let's say you're a reseller and you're selling books.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:03,000 --> 00:02:04,000
|
| 135 |
+
Okay.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:04,000 --> 00:02:07,000
|
| 139 |
+
Each block for you holds three transactions.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:07,000 --> 00:02:12,000
|
| 143 |
+
It holds who bought the book when they bought the book, and how much money they spent buying the book.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:12,000 --> 00:02:13,000
|
| 147 |
+
And again, this is a list.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:13,000 --> 00:02:18,000
|
| 151 |
+
Anything that you can, anything that you can put a make a list out of, you can make a blockchain out
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:18,000 --> 00:02:18,000
|
| 155 |
+
of.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:18,000 --> 00:02:21,000
|
| 159 |
+
So let's say each block holds three transactions.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:21,000 --> 00:02:26,000
|
| 163 |
+
And I'll show you why the blockchain is so powerful and why people like using it.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:26,000 --> 00:02:28,000
|
| 167 |
+
So each block is three transactions.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:28,000 --> 00:02:32,000
|
| 171 |
+
So in the first block you put transaction number one.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:32,000 --> 00:02:38,000
|
| 175 |
+
Let's say Bob bought a book for $10 and the book was, uh, Excel.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:38,000 --> 00:02:45,000
|
| 179 |
+
Then the second book was bought by Mary for 20 bucks, and she bought a word book.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:45,000 --> 00:02:49,000
|
| 183 |
+
And, uh, number three was Peter.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:49,000 --> 00:02:54,000
|
| 187 |
+
He bought a CISSP book for a $30 CISSP book.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:54,000 --> 00:02:55,000
|
| 191 |
+
It doesn't matter what it is.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:55,000 --> 00:02:58,000
|
| 195 |
+
Just know it's three transaction.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:58,000 --> 00:03:06,000
|
| 199 |
+
What you do is you take your entire three transaction, all three of them, everything about them,
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:06,000 --> 00:03:07,000
|
| 203 |
+
and you hash it.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:07,000 --> 00:03:14,000
|
| 207 |
+
Now, the most famous hash they use is a crypto is a, uh, Sha 256 is the most famous hash they use.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:14,000 --> 00:03:19,000
|
| 211 |
+
If you remember the hash in videos, how I was able to type text in the box and they generate a hash,
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:19,000 --> 00:03:20,000
|
| 215 |
+
the same thing here.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:20,000 --> 00:03:23,000
|
| 219 |
+
They're just going to put all the transaction in and boom, generate a hash.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:23,000 --> 00:03:26,000
|
| 223 |
+
This is the hash that comes out of this block.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:27,000 --> 00:03:29,000
|
| 227 |
+
There is no previous hash or zero.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:30,000 --> 00:03:31,000
|
| 231 |
+
Then what they do?
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:32,000 --> 00:03:40,000
|
| 235 |
+
Is they go to the next block and they put another one, two, three transaction.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:40,000 --> 00:03:41,000
|
| 239 |
+
Whatever they are, it doesn't matter for now.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:42,000 --> 00:03:45,000
|
| 243 |
+
And then they hash it.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:45,000 --> 00:03:46,000
|
| 247 |
+
But here's what they do.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:46,000 --> 00:03:50,000
|
| 251 |
+
This block starts out with the this previous hash.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:50,000 --> 00:03:55,000
|
| 255 |
+
This hash comes right here 6UP2.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:55,000 --> 00:04:02,000
|
| 259 |
+
So it takes the three transaction plus this hash to produce this hash.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:02,000 --> 00:04:11,000
|
| 263 |
+
Then it takes this hash puts it here I'm talking the hash value itself 8Y5C9.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:11,000 --> 00:04:14,000
|
| 267 |
+
And then it does 123 transaction.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:15,000 --> 00:04:16,000
|
| 271 |
+
And it.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:17,000 --> 00:04:18,000
|
| 275 |
+
And it gets a hash.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:18,000 --> 00:04:20,000
|
| 279 |
+
Now this is great.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:20,000 --> 00:04:21,000
|
| 283 |
+
Why is this good?
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:21,000 --> 00:04:22,000
|
| 287 |
+
This is a blockchain.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:22,000 --> 00:04:25,000
|
| 291 |
+
If you ever wanted to know what exactly is a blockchain, this is how it works.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:25,000 --> 00:04:26,000
|
| 295 |
+
Why is this good?
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:26,000 --> 00:04:32,000
|
| 299 |
+
Because remember in the world of hashing, if anything changes, it changes all of the files within
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:32,000 --> 00:04:33,000
|
| 303 |
+
it, right?
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:33,000 --> 00:04:37,000
|
| 307 |
+
If anything changes, if if anything changes in the transaction, the hash will change.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:37,000 --> 00:04:39,000
|
| 311 |
+
This is a this is a great technology.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:39,000 --> 00:04:46,000
|
| 315 |
+
And the reason we do this is because if anyone ever manipulates a transaction, let's say any one of
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:46,000 --> 00:04:48,000
|
| 319 |
+
these first transaction.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:49,000 --> 00:04:55,000
|
| 323 |
+
Then this hash will change, which will then invalidate this hash, which will then invalidate this
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:55,000 --> 00:04:56,000
|
| 327 |
+
hash.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:56,000 --> 00:05:01,000
|
| 331 |
+
In other words, any time you manipulate a block, all the block that goes forward after that becomes
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:01,000 --> 00:05:02,000
|
| 335 |
+
invalidated.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:03,000 --> 00:05:04,000
|
| 339 |
+
And here's a pretty cool part.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:05,000 --> 00:05:12,000
|
| 343 |
+
This ledger, this block chain, these lists of blocks or all these blocks are stored across thousands
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:12,000 --> 00:05:14,000
|
| 347 |
+
of machines across your network.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:14,000 --> 00:05:16,000
|
| 351 |
+
They all have the exact same ledger.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:16,000 --> 00:05:19,000
|
| 355 |
+
So when somebody manipulates this one, they'll be able to tell, hey, you know what?
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:19,000 --> 00:05:21,000
|
| 359 |
+
That ledger is different than my ledger.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:21,000 --> 00:05:22,000
|
| 363 |
+
What's the difference here?
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:22,000 --> 00:05:24,000
|
| 367 |
+
So it's decentralized.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:24,000 --> 00:05:27,000
|
| 371 |
+
Decentralized means it's not stored on a single machine.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:27,000 --> 00:05:29,000
|
| 375 |
+
In fact, it's stored on tons of machines.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:29,000 --> 00:05:33,000
|
| 379 |
+
If anybody ever does a manipulation, it updates all the ledgers, and people are going to see.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:33,000 --> 00:05:39,000
|
| 383 |
+
Well, technically, the only blocks that should ever be manipulated is this block four.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:39,000 --> 00:05:40,000
|
| 387 |
+
Then block five.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:40,000 --> 00:05:43,000
|
| 391 |
+
If anybody is changing blocks 2 or 3, that's a problem.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:43,000 --> 00:05:45,000
|
| 395 |
+
So that's the concept of a blockchain.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:45,000 --> 00:05:51,000
|
| 399 |
+
Now one thing that you may see pop up on your exam is a firm we call an open public ledger.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:52,000 --> 00:05:54,000
|
| 403 |
+
This is a decentralized and transparent record.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:54,000 --> 00:05:58,000
|
| 407 |
+
Keeping the ledger is accessible to anyone provides a permanent record of all transactions.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:58,000 --> 00:06:05,000
|
| 411 |
+
Now, there are websites out there that has all of the crypto currency transaction.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:05,000 --> 00:06:09,000
|
| 415 |
+
So if you ever find somebody who's cryptocurrency number.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:11,000 --> 00:06:16,000
|
| 419 |
+
Uh, you can actually put it into the public ledger, and the ledger is going to show you all the transactions
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:16,000 --> 00:06:17,000
|
| 423 |
+
against that.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:17,000 --> 00:06:25,000
|
| 427 |
+
So all the transactions that you take, utilize in a particular cryptocurrency is public to everyone.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:25,000 --> 00:06:29,000
|
| 431 |
+
So they could see that this was used to purchase this, this and this was used in these transactions,
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:29,000 --> 00:06:30,000
|
| 435 |
+
but they don't know who owns it.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:31,000 --> 00:06:34,000
|
| 439 |
+
So that is what a public ledger is.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:35,000 --> 00:06:42,000
|
| 443 |
+
Once again, keep in mind that, uh, blockchains is not something unique only to cryptocurrency.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:42,000 --> 00:06:46,000
|
| 447 |
+
Although it was pretty much invented with crypto, the creation of Bitcoin, it's not being utilized
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:46,000 --> 00:06:50,000
|
| 451 |
+
in tons of applications, so make sure you're familiar with it.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:50,000 --> 00:06:51,000
|
| 455 |
+
It's all about integrity.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:51,000 --> 00:06:58,000
|
| 459 |
+
Public ledgers, especially blockchains, is not about confidentiality because technically in a public
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:58,000 --> 00:06:59,000
|
| 463 |
+
ledger, it's all available.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:59,000 --> 00:07:01,000
|
| 467 |
+
The big key word there is integrity.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:01,000 --> 00:07:06,000
|
| 471 |
+
That means that if anybody manipulates any transaction on the blockchain, you're going to be able to
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:06,000 --> 00:07:12,000
|
| 475 |
+
detect it, making it one of the best technologies, best in upcoming technologies going forward.
|
| 476 |
+
|
07 - Cryptography/023 Salting OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,352 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:06,000
|
| 3 |
+
One of the worst technologies that still exists today that secures almost all the data on the planet
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:06,000 --> 00:00:07,000
|
| 7 |
+
is passwords.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:07,000 --> 00:00:08,000
|
| 11 |
+
Oh, I hate passwords.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:08,000 --> 00:00:10,000
|
| 15 |
+
There's so many passwords to remember.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:10,000 --> 00:00:16,000
|
| 19 |
+
You always got to remember a complex password, and then it's easily hacked unless we salt it.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:16,000 --> 00:00:20,000
|
| 23 |
+
In this video, I want to talk about a topic called Sultan.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:20,000 --> 00:00:24,000
|
| 27 |
+
And Sultan is predominantly used to secure passwords.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:29,000
|
| 31 |
+
Now, I do have a link in an article we're going to look at on Wikipedia that really shows in depth
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:29,000 --> 00:00:30,000
|
| 35 |
+
salt.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:30,000 --> 00:00:33,000
|
| 39 |
+
And I want to explain this to you guys, but what exactly is it?
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:33,000 --> 00:00:37,000
|
| 43 |
+
So Sultan is used to enhance the security of stored passwords.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:37,000 --> 00:00:38,000
|
| 47 |
+
It involves listen carefully.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:38,000 --> 00:00:47,000
|
| 51 |
+
Add in a unique random string of characters known as a salt to each password before it's hashed.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:47,000 --> 00:00:50,000
|
| 55 |
+
Now, in order to move on, you got to understand something.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:50,000 --> 00:00:54,000
|
| 59 |
+
When you store a password, a computer does not store the plaintext.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:54,000 --> 00:00:58,000
|
| 63 |
+
So if your password is password one, two, three, it doesn't store password 123.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:58,000 --> 00:01:00,000
|
| 67 |
+
It stores the hash of that.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:01,000 --> 00:01:02,000
|
| 71 |
+
Now remember I showed you guys hashing.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:03,000 --> 00:01:05,000
|
| 75 |
+
So it will store just the hash value.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:05,000 --> 00:01:12,000
|
| 79 |
+
When you come back to type in your password, it just you type in password one, two, three then hashes
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:12,000 --> 00:01:14,000
|
| 83 |
+
it and compare it to the hash it has.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:14,000 --> 00:01:16,000
|
| 87 |
+
If it matches up boom, it logs you in.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:16,000 --> 00:01:17,000
|
| 91 |
+
That's the normal operation.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:17,000 --> 00:01:20,000
|
| 95 |
+
But how does Sultan work?
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:20,000 --> 00:01:23,000
|
| 99 |
+
Well, I have the process listed here.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:24,000 --> 00:01:26,000
|
| 103 |
+
Okay, in case you're reading this at a later time.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:27,000 --> 00:01:32,000
|
| 107 |
+
Uh, but I want to go to this article, uh, on Wikipedia, and I want to show it to you, actually,
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:32,000 --> 00:01:34,000
|
| 111 |
+
uh, more and more in practice.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:34,000 --> 00:01:39,000
|
| 115 |
+
So let's go to that link that you see on the slide.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:39,000 --> 00:01:40,000
|
| 119 |
+
Um.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:41,000 --> 00:01:43,000
|
| 123 |
+
And here we go.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:44,000 --> 00:01:47,000
|
| 127 |
+
Okay, so here's the link I just put on the slide there.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:47,000 --> 00:01:48,000
|
| 131 |
+
And this is going to be Sultan.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:48,000 --> 00:01:50,000
|
| 135 |
+
Now I want to show you guys a couple of things.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:50,000 --> 00:01:51,000
|
| 139 |
+
First of all.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:53,000 --> 00:01:55,000
|
| 143 |
+
So here is user one.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:55,000 --> 00:01:57,000
|
| 147 |
+
This is their password.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:01:57,000 --> 00:01:59,000
|
| 151 |
+
This is the hash of their password.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:00,000 --> 00:02:00,000
|
| 155 |
+
Okay.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:00,000 --> 00:02:01,000
|
| 159 |
+
That's the.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:01,000 --> 00:02:05,000
|
| 163 |
+
This is the 256 bit hash that's generated by Sha 256.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:06,000 --> 00:02:15,000
|
| 167 |
+
What the computer does with Sultan is that instead of just having the hash of just this password, what
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:15,000 --> 00:02:17,000
|
| 171 |
+
the computer does is that it generates a salt.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:17,000 --> 00:02:22,000
|
| 175 |
+
This thing, it's a random set of a string of characters.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:22,000 --> 00:02:28,000
|
| 179 |
+
What it does now is that it will append this to your password.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:29,000 --> 00:02:31,000
|
| 183 |
+
Notice this is your password 123.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:32,000 --> 00:02:36,000
|
| 187 |
+
And then it appends all this random stuff to it and then hashes this.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:38,000 --> 00:02:41,000
|
| 191 |
+
Ash is all the things I just highlighted to form this.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:41,000 --> 00:02:46,000
|
| 195 |
+
So what's stored in the computer's password file is not this hash of password one, two, three.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:46,000 --> 00:02:47,000
|
| 199 |
+
It's this thing.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:47,000 --> 00:02:51,000
|
| 203 |
+
And this is incredibly difficult to crack.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:51,000 --> 00:02:54,000
|
| 207 |
+
Very few brute force in modern time will ever crack this.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:54,000 --> 00:02:57,000
|
| 211 |
+
Look how long this is, and look how complex it is.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:58,000 --> 00:03:05,000
|
| 215 |
+
So what it does is that it will take your password, append the salt, then hash it and then store it.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:06,000 --> 00:03:11,000
|
| 219 |
+
When you come to log in, the verification process would be you type in password one, two, three.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:11,000 --> 00:03:12,000
|
| 223 |
+
You never know assault.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:12,000 --> 00:03:13,000
|
| 227 |
+
You type in password 123.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:13,000 --> 00:03:19,000
|
| 231 |
+
It then re appends the salt, rehashes it and see oh okay.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:19,000 --> 00:03:20,000
|
| 235 |
+
Does it match what they have?
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:20,000 --> 00:03:21,000
|
| 239 |
+
Yes okay.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:21,000 --> 00:03:22,000
|
| 243 |
+
It's correct.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:22,000 --> 00:03:27,000
|
| 247 |
+
Now if you're wondering does this really increase the security?
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:27,000 --> 00:03:29,000
|
| 251 |
+
The answer is absolutely.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:31,000 --> 00:03:36,000
|
| 255 |
+
You see, one of the things here we have to remember, some people say, well, if I come to the prompt
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:36,000 --> 00:03:38,000
|
| 259 |
+
and I keep typing in the past one, it might crack it.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:38,000 --> 00:03:44,000
|
| 263 |
+
You see, the way they crack password is they steal the hash, and then they run a brute force attack
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:44,000 --> 00:03:45,000
|
| 267 |
+
against the hash.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:45,000 --> 00:03:49,000
|
| 271 |
+
No one knows your password except your head, except your brain.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:49,000 --> 00:03:51,000
|
| 275 |
+
But they know the hash.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:51,000 --> 00:03:54,000
|
| 279 |
+
The hash is technically not that difficult to get.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:54,000 --> 00:03:58,000
|
| 283 |
+
And if they get a hash that has a whole bunch of random string of character, what they're going to
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:58,000 --> 00:04:00,000
|
| 287 |
+
do is they're going to brute force that hash.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:00,000 --> 00:04:04,000
|
| 291 |
+
And even if they guess the hash, that's technically not your password because your password is one,
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:04,000 --> 00:04:05,000
|
| 295 |
+
two, three.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:05,000 --> 00:04:13,000
|
| 299 |
+
So if they use a massive super alien machine to crack that hash and find out your password with the
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:13,000 --> 00:04:15,000
|
| 303 |
+
salt, it's not your password.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:15,000 --> 00:04:16,000
|
| 307 |
+
Because you know what?
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:16,000 --> 00:04:21,000
|
| 311 |
+
When they type in your password, which they believe is your password, one, two, three plus the salt
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:21,000 --> 00:04:24,000
|
| 315 |
+
is then going to re append the old salt.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:25,000 --> 00:04:26,000
|
| 319 |
+
And it's never going to work.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:26,000 --> 00:04:35,000
|
| 323 |
+
Sultan, remember, drastically improves your passwords, drastically improves the password.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:35,000 --> 00:04:37,000
|
| 327 |
+
Now you have to set this up.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:37,000 --> 00:04:43,000
|
| 331 |
+
Sultan is done in many applications and web applications especially will utilize Sultan.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:43,000 --> 00:04:47,000
|
| 335 |
+
So Sultan is an important topic in the world of IT security.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:47,000 --> 00:04:53,000
|
| 339 |
+
Anytime you hear someone do or build in a web application, ask them will the password be salted?
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:53,000 --> 00:04:56,000
|
| 343 |
+
If not as an IT security security professional?
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:56,000 --> 00:05:01,000
|
| 347 |
+
Tell them, I would highly recommend you salt the password.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:01,000 --> 00:05:04,000
|
| 351 |
+
That way the system is super secure.
|
| 352 |
+
|
07 - Cryptography/024 TPM OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,284 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
One of the most dangerous things that can ever happen in the world of it is when you're a security administrator
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:12,000
|
| 7 |
+
and you get a call that one of your employee has lost their laptop, because on this laptop contains
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:12,000 --> 00:00:18,000
|
| 11 |
+
all the company's data, all that person's email, it doesn't matter how secure their password is.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:18,000 --> 00:00:23,000
|
| 15 |
+
You see, if I want the data off of this laptop, I don't need to know your password.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:23,000 --> 00:00:31,000
|
| 19 |
+
All I got to do unscrew the bottom, take out the bottom, take out the hard drive, take that hard
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:31,000 --> 00:00:33,000
|
| 23 |
+
drive and mount it to my computer.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:33,000 --> 00:00:36,000
|
| 27 |
+
Whether it's a Sata drive Mdot, it doesn't matter.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:36,000 --> 00:00:38,000
|
| 31 |
+
I'm just going to plug the drive into my machine.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:38,000 --> 00:00:44,000
|
| 35 |
+
And there's a lot of external Mdot two and Sata connectors and whatever I can use to externally mount
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:44,000 --> 00:00:47,000
|
| 39 |
+
your hard drive onto my desktop.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:47,000 --> 00:00:51,000
|
| 43 |
+
And now I can open all the files on your hard drive.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:51,000 --> 00:00:53,000
|
| 47 |
+
I don't care about logging into your windows.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:53,000 --> 00:00:55,000
|
| 51 |
+
All I want to do is steal your data.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:55,000 --> 00:01:00,000
|
| 55 |
+
This is a nightmare scenario for any it department.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:00,000 --> 00:01:03,000
|
| 59 |
+
So what do we do with devices like this?
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:03,000 --> 00:01:05,000
|
| 63 |
+
Or god forbid, even more devices like this?
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:05,000 --> 00:01:11,000
|
| 67 |
+
You see, especially when it comes to computers like this, we need to do what is called hard drive
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:11,000 --> 00:01:12,000
|
| 71 |
+
encryption.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:13,000 --> 00:01:16,000
|
| 75 |
+
We need to encrypt the hard drive.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:16,000 --> 00:01:21,000
|
| 79 |
+
That way, if anybody does what I just say, I've taken the hard drive out, mounted it to a machine,
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:21,000 --> 00:01:24,000
|
| 83 |
+
and seeing all the files in it, they won't be able to see anything.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:24,000 --> 00:01:26,000
|
| 87 |
+
Because the drive is encrypted.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:26,000 --> 00:01:28,000
|
| 91 |
+
The drive has to be encrypted.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:28,000 --> 00:01:30,000
|
| 95 |
+
This is called disk encryption.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:30,000 --> 00:01:38,000
|
| 99 |
+
And one of the ways of doing that is by utilizing oops, a TPM or a TPM chip.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:38,000 --> 00:01:44,000
|
| 103 |
+
A lot of these corporate laptops comes built with something we call a TPM chip.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:45,000 --> 00:01:52,000
|
| 107 |
+
TPM Trusted Platform module is a hardware component designed to secure hardware by integrating cryptographic
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:52,000 --> 00:01:53,000
|
| 111 |
+
keys.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:53,000 --> 00:01:59,000
|
| 115 |
+
It's basically a device, okay that allows the generation of storage of cryptographic keys.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:59,000 --> 00:02:04,000
|
| 119 |
+
TPMs can generate encryption keys, keeping them private, keeping the private portion of these keys
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:04,000 --> 00:02:06,000
|
| 123 |
+
safe within a TPM chip itself.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:07,000 --> 00:02:10,000
|
| 127 |
+
Now it's used for multiple purposes.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:10,000 --> 00:02:14,000
|
| 131 |
+
Number one, it's used to do things like disk encryption.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:14,000 --> 00:02:16,000
|
| 135 |
+
Now if you have windows.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:17,000 --> 00:02:19,000
|
| 139 |
+
Windows 11, and so on.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:19,000 --> 00:02:24,000
|
| 143 |
+
Windows 10 11, the higher versions of it, the business editions of it, you can have BitLocker, like
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:24,000 --> 00:02:26,000
|
| 147 |
+
I have BitLocker on this machine.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:26,000 --> 00:02:28,000
|
| 151 |
+
I also have BitLocker on this machine.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:28,000 --> 00:02:31,000
|
| 155 |
+
You turn on BitLocker encryption.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:31,000 --> 00:02:37,000
|
| 159 |
+
And what BitLocker does if the machine has a TPM chip, is that it will encrypt the hard drive and it'll
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:37,000 --> 00:02:40,000
|
| 163 |
+
store the cryptographic keys on the TPM chip.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:40,000 --> 00:02:46,000
|
| 167 |
+
If you remove the hard drive, you wouldn't be able to see anything because you'll need to decrypt it.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:46,000 --> 00:02:50,000
|
| 171 |
+
But the cryptographic keys is on the TPM chip.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:50,000 --> 00:02:53,000
|
| 175 |
+
Now, the TPM chip will be like something that's sorted into the motherboard.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:53,000 --> 00:02:56,000
|
| 179 |
+
It wouldn't be able something you could just rip off.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:57,000 --> 00:03:02,000
|
| 183 |
+
The TPM can also store and manage keys using the process of verifying the boot process.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:03:02,000 --> 00:03:06,000
|
| 187 |
+
That way no malware can try to load up in the boot process.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:06,000 --> 00:03:10,000
|
| 191 |
+
So TPM is super important right now.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:10,000 --> 00:03:13,000
|
| 195 |
+
If you're managing an IT department, you must.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:13,000 --> 00:03:21,000
|
| 199 |
+
And I say you must ensure that all your laptops especially have TPM, anything that's mobile.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:22,000 --> 00:03:25,000
|
| 203 |
+
So exactly what is it?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:25,000 --> 00:03:30,000
|
| 207 |
+
Well, it's basically it's a secure it has what's called a crypto processor that's designed to carry
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:30,000 --> 00:03:32,000
|
| 211 |
+
out cryptographic operations.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:32,000 --> 00:03:39,000
|
| 215 |
+
The primary purpose of it, once again, is to ensure that we create cryptographic keys to keep our
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:39,000 --> 00:03:40,000
|
| 219 |
+
disk secure.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:40,000 --> 00:03:45,000
|
| 223 |
+
This is going to be the two main beneficial aspects of a TPM chip.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:45,000 --> 00:03:47,000
|
| 227 |
+
I can't emphasize this enough.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:47,000 --> 00:03:48,000
|
| 231 |
+
One time.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:49,000 --> 00:03:55,000
|
| 235 |
+
Now this actually, this laptop actually has, uh, a TPM chip.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:55,000 --> 00:03:56,000
|
| 239 |
+
It is fully encrypted.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:56,000 --> 00:04:01,000
|
| 243 |
+
It does have the data of the business on it because it has my email and I am the CEO of the business.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:04:01,000 --> 00:04:03,000
|
| 247 |
+
It has my email, it has work I'm working on.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:04:04,000 --> 00:04:06,000
|
| 251 |
+
And one time I left it in the back of an Uber.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:04:07,000 --> 00:04:09,000
|
| 255 |
+
And you know, it didn't bother me much.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:09,000 --> 00:04:12,000
|
| 259 |
+
I called the Uber like the moment I figured out I left it.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:12,000 --> 00:04:17,000
|
| 263 |
+
It didn't like my heart didn't sink because I realized, well, even if somebody steals this laptop.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:18,000 --> 00:04:20,000
|
| 267 |
+
My password is super secure.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:20,000 --> 00:04:23,000
|
| 271 |
+
They probably not be able to get in, but if they do take the hard drive out.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:24,000 --> 00:04:28,000
|
| 275 |
+
They'll never get anything out of it, because the TPM in which obviously the laptop is back with me,
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:28,000 --> 00:04:30,000
|
| 279 |
+
I called Uber and the driver dropped it back.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:30,000 --> 00:04:35,000
|
| 283 |
+
So make sure you use TPM chips, especially on all mobile devices.
|
| 284 |
+
|
07 - Cryptography/025 Secure Enclave OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,124 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
When a computer is processing data, one of the things that the computer must be able to do, especially
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:09,000
|
| 7 |
+
secure processing, is that it has to be able to like segment that off.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:09,000 --> 00:00:16,000
|
| 11 |
+
You don't want things like processing of thumbprints or passwords to just be in any place of memory.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:16,000 --> 00:00:21,000
|
| 15 |
+
We have this concept called a secure enclave.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:21,000 --> 00:00:25,000
|
| 19 |
+
This provides a highly secure space within a device.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:25,000 --> 00:00:29,000
|
| 23 |
+
Memory, where sensitive data can be stored in cryptographic operations is done on.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:29,000 --> 00:00:33,000
|
| 27 |
+
And this basically isolates it from the other operating systems and processes.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:33,000 --> 00:00:35,000
|
| 31 |
+
Why would you do this?
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:35,000 --> 00:00:43,000
|
| 35 |
+
Well, cryptographic processes generally in things does things like encrypt and decrypt sensitive data.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:43,000 --> 00:00:48,000
|
| 39 |
+
It checks things like passwords or facial recognition or biometrics.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:48,000 --> 00:00:51,000
|
| 43 |
+
You don't want this to just be in any part of a computer memory.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:51,000 --> 00:00:51,000
|
| 47 |
+
Why?
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:51,000 --> 00:00:55,000
|
| 51 |
+
Because then other programs can read it and steal that data.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:55,000 --> 00:01:01,000
|
| 55 |
+
So what we do is we set up secure enclaves, and this is going to be done within the actual software
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:01,000 --> 00:01:02,000
|
| 59 |
+
and hardware.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:03,000 --> 00:01:04,000
|
| 63 |
+
So what does it do?
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:04,000 --> 00:01:10,000
|
| 67 |
+
Well, it ensures that sensitive data, like fingerprints, is stored in an environment that is separated,
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:10,000 --> 00:01:12,000
|
| 71 |
+
segregated from the rest of the operating system.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:12,000 --> 00:01:14,000
|
| 75 |
+
This protects it from any malware.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:14,000 --> 00:01:19,000
|
| 79 |
+
So let's say you don't even know you have malicious software in your machine.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:20,000 --> 00:01:25,000
|
| 83 |
+
So you try to decode a file or log in with something, let's say a thumbprint.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:26,000 --> 00:01:30,000
|
| 87 |
+
Well, you don't really have to worry too much about the malware getting it, because you're using this
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:30,000 --> 00:01:33,000
|
| 91 |
+
concept on your operating system and on your hardware.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:34,000 --> 00:01:39,000
|
| 95 |
+
Some of the key features, basically hardware isolation, the data and operations with data are isolated
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:39,000 --> 00:01:42,000
|
| 99 |
+
at the hardware level, so software can't break it.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:42,000 --> 00:01:47,000
|
| 103 |
+
It limits access and is generally considered tamper resistant, making physical attacks very difficult
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:47,000 --> 00:01:50,000
|
| 107 |
+
to get it on high secure systems.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:50,000 --> 00:01:56,000
|
| 111 |
+
This is one of the things you're going to have to make sure is built into the system, because you could
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:56,000 --> 00:02:02,000
|
| 115 |
+
have malware or malicious software on your machine and not know it, and then secure operations could
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:02,000 --> 00:02:04,000
|
| 119 |
+
be taking place in the malware can be stealing it.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:04,000 --> 00:02:08,000
|
| 123 |
+
But if you use a secure enclave, that is much less likely to happen.
|
| 124 |
+
|
07 - Cryptography/026 Obfuscation OB 1.4_en.srt
ADDED
|
@@ -0,0 +1,252 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:06,000
|
| 3 |
+
Sometimes when you are playing around with data or have to have test data, you have to be careful because
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:06,000 --> 00:00:09,000
|
| 7 |
+
a lot of data in the business is considered confidential.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:09,000 --> 00:00:13,000
|
| 11 |
+
But sometimes when you're building an application, you need data to work with.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:13,000 --> 00:00:16,000
|
| 15 |
+
You need large data sets to actually work with.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:16,000 --> 00:00:22,000
|
| 19 |
+
Now in this video, I want to show you guys a topic we're going to refer to as data obfuscation.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:22,000 --> 00:00:28,000
|
| 23 |
+
Obfuscation is basically the process of disguising sensitive, confidential or sensitive data protected
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:28,000 --> 00:00:30,000
|
| 27 |
+
basically from unauthorized access.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:30,000 --> 00:00:32,000
|
| 31 |
+
Now I'm going to try this.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:32,000 --> 00:00:32,000
|
| 35 |
+
Here.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:32,000 --> 00:00:35,000
|
| 39 |
+
We have another video coming up on tokenization.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:35,000 --> 00:00:38,000
|
| 43 |
+
But I'm going to I want to show you guys what obfuscation is going to do.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:39,000 --> 00:00:42,000
|
| 47 |
+
And I'm going to go to that link and I want to show you guys what it does.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:42,000 --> 00:00:45,000
|
| 51 |
+
So basically it's going to hide the data.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:45,000 --> 00:00:51,000
|
| 55 |
+
Let's say you're writing a program like your source code to the program in order to make it difficult
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:51,000 --> 00:00:53,000
|
| 59 |
+
for people to find the original source code.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:53,000 --> 00:00:57,000
|
| 63 |
+
If they see the source code they decompile the program is you can obfuscate it.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:57,000 --> 00:00:58,000
|
| 67 |
+
Let me show you guys what it looks like.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:58,000 --> 00:01:02,000
|
| 71 |
+
So if you follow that link in this slide there, this is what you would have gotten.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:02,000 --> 00:01:07,000
|
| 75 |
+
And here's this is a JavaScript Obfuscator tool.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:07,000 --> 00:01:15,000
|
| 79 |
+
And you notice that this is this is basically just the JavaScript that when ran it just says hello world.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:15,000 --> 00:01:18,000
|
| 83 |
+
It's the first thing you learn when you learn JavaScript or Java in general.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:18,000 --> 00:01:22,000
|
| 87 |
+
This is a comment that says paste your JavaScript code here.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:22,000 --> 00:01:24,000
|
| 91 |
+
Now this is going to obfuscate it.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:24,000 --> 00:01:25,000
|
| 95 |
+
So you can use this.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:25,000 --> 00:01:28,000
|
| 99 |
+
You can actually put your code in here if you write code and obfuscate it.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:28,000 --> 00:01:30,000
|
| 103 |
+
So if I say obfuscate watch what happens.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:30,000 --> 00:01:33,000
|
| 107 |
+
Ooh, that looks kind of crazy doesn't it?
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:33,000 --> 00:01:37,000
|
| 111 |
+
Now if you run this code.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:38,000 --> 00:01:38,000
|
| 115 |
+
Okay.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:38,000 --> 00:01:44,000
|
| 119 |
+
If you run this code, it will run the code that we saw here.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:44,000 --> 00:01:49,000
|
| 123 |
+
This output obfuscated code technically is this.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:49,000 --> 00:01:54,000
|
| 127 |
+
Except as you notice, it looks kind of crazy.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:56,000 --> 00:01:56,000
|
| 131 |
+
It's obfuscate that.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:57,000 --> 00:01:59,000
|
| 135 |
+
So it's actually all there.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:59,000 --> 00:02:01,000
|
| 139 |
+
But it is difficult.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:01,000 --> 00:02:04,000
|
| 143 |
+
It basically hides a lot of the code, but it's still usable.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:05,000 --> 00:02:09,000
|
| 147 |
+
Now there are some other ways here that we can do.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:09,000 --> 00:02:10,000
|
| 151 |
+
Obfuscation.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:10,000 --> 00:02:14,000
|
| 155 |
+
What I showed you there is basically like a code code obfuscation, but it tells you the principle that
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:14,000 --> 00:02:18,000
|
| 159 |
+
basically you're hiding your sensitive data.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:18,000 --> 00:02:20,000
|
| 163 |
+
There are a couple of things here we want to talk about.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:21,000 --> 00:02:22,000
|
| 167 |
+
First of all.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:22,000 --> 00:02:23,000
|
| 171 |
+
Data masking.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:23,000 --> 00:02:28,000
|
| 175 |
+
Data masking is when you create a substitute version of a data set.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:28,000 --> 00:02:32,000
|
| 179 |
+
The values are changed, but the data but the format remains the same.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:32,000 --> 00:02:36,000
|
| 183 |
+
An organization can run tests or training sessions if they were using real data.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:36,000 --> 00:02:41,000
|
| 187 |
+
So let's say you have a let's say you made a financial application and you got to test how credit cards,
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:41,000 --> 00:02:44,000
|
| 191 |
+
you know, how much credit cards it can hold when instead of putting in real credit card numbers, just
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:44,000 --> 00:02:49,000
|
| 195 |
+
take the take the actual credit card number and create a different version of it that's not real, and
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:49,000 --> 00:02:50,000
|
| 199 |
+
then use that data.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:50,000 --> 00:02:50,000
|
| 203 |
+
Masking.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:51,000 --> 00:02:56,000
|
| 207 |
+
Encryption is something that we have spent an enormous amount of time in the encryption section on.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:56,000 --> 00:03:00,000
|
| 211 |
+
So remember encryption will hide the meaning of information.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:00,000 --> 00:03:01,000
|
| 215 |
+
It's part of what it does.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:02,000 --> 00:03:05,000
|
| 219 |
+
The next thing you're going to want to be familiar with is called tokenization.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:05,000 --> 00:03:09,000
|
| 223 |
+
Tokenization, depending on the exam you're taking, will be covered on your test.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:09,000 --> 00:03:14,000
|
| 227 |
+
Tokenization creates tokens to represent certain data.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:14,000 --> 00:03:16,000
|
| 231 |
+
Keep an eye on that door in the next video when I cover it.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:17,000 --> 00:03:21,000
|
| 235 |
+
But obfuscation is something that is important there.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:21,000 --> 00:03:25,000
|
| 239 |
+
They come up lots of times when you have to use sensitive data.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:25,000 --> 00:03:30,000
|
| 243 |
+
You want to process sensitive data without actually having the sensitive data.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:30,000 --> 00:03:31,000
|
| 247 |
+
You'll see what I mean next.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:31,000 --> 00:03:32,000
|
| 251 |
+
Tokenization.
|
| 252 |
+
|