تدريب Shadowing: Crypto Agility Explained: Protect Data from Quantum Computing Threats - تعلم التحدث بالإنجليزية عبر الفيديو
جارٍ إنشاء الدرس...
1
I want you to remember four words.
2
If you remember nothing else out of this video than these four, I'll consider it a success.
3
Here they are.
4
Harvest now, decrypt later.
5
What does that mean?
6
Well, it means the future is coming to steal your data.
7
Not in some sci -fi movie plot sort of way, but in a very realistic scenario.
8
It means that you can encrypt all of your sensitive data today, and in the not -too -distant future, it suddenly won't be secret anymore.
9
If those secrets are time sensitive and won't mean much in a few months or years, then probably you don't need to worry.
10
But if they do have value going forward, then please listen up as we unpack what those four words mean.
11
Harvest now, decrypt later.
12
Okay, let's go back and give some context.
13
Sensitive data, like an organization's intellectual property or client data, we'll call it personally identifiable information,
14
or other secrets like that need to be protected from prying eyes.
15
Only those with a need to know should have access.
16
So, we use cryptography to protect these secrets.
17
Plain text like this goes into a crypto algorithm,
18
and we use a randomly generated key to turn plain text that's readable into ciphertext that is not.
19
And that ciphertext can then be transmitted over a public network network
20
or stored in a database without fear that an attacker will be able to read it.
21
Then when we need to reverse the process for an authorized user, we decrypt the ciphertext and get back to the original message.
22
Sounds great.
23
And it all works.
24
In fact, we rely on this technology every day for all sorts of important personal and business transactions.
25
Crypto works, though, because there are certain hard mathematical problems built into the algorithms
26
that we use that even the most powerful supercomputers can't solve in a thousand years.
27
That's why your secrets are secret.
28
But a disruptive new technology is on its way
29
that threatens to upend this arrangement if we aren't careful to prepare for it.
30
Quantum computers are amazing.
31
They leverage physical properties that defy conventional logic.
32
They will literally save lives as we're able to use them to develop more effective drug therapies to treat diseases, and that's really just the beginning.
33
Put simply, they have the potential to solve in a few hours certain types of problems
34
that would take many lifetimes to work out on today's classical computers.
35
Sounds great, right?
36
Well, one of those hard problems also just happens to be the basis for how our classical crypto works.
37
In other words, quantum will do great things, but it also has the potential to break all of our existing cryptography.
38
and that's going to be a problem.
39
Suddenly the secrets aren't secret anymore.
40
When will it do this?
41
Well, nobody really knows for sure.
42
The consensus in the crypto community seems to be that it will probably be in the next five to ten years, but it could happen tomorrow.
43
If someone discovers a novel way to use the power of today's quantum systems, then suddenly the whole thing falls.
44
So don't get too comfortable, because unlike Y2K, this could hit us at any time without warning.
45
But let's assume that doesn't happen.
46
Then why bother with this hypothetical now?
47
Why not just wake you up in a few years when this becomes an actual threat?
48
Well, because of these words I mentioned at the beginning, harvest now, decrypt later.
49
In fact, a bad guy could right now make a copy of your encrypted data and just hold on to it.
50
can't read it, but maybe he sees this as it goes across a network.
51
Maybe he sees an encrypted database that you have that's a backup and makes a copy of that.
52
All he has to do is hold on to that and then wait for the future to come to him.
53
Because in the future you'll be able to use a quantum computer, feed this information in, and be able to read the data,
54
get back to the plain text that he was actually looking for.
55
Another way of looking at it is to imagine
56
if you had a time machine and you could travel into the future
57
and bring back with you a super powerful quantum system.
58
Now you would be able to break all the encrypted messages at will.
59
What would be the impact of such a scenario?
60
Well, as I mentioned before, sensitive information like intellectual property, PII, things like that, even national secrets would be revealed.
61
Digital signatures could be forged, electronic records would no longer become reliable, payment systems would be broken,
62
the security of critical infrastructure like the power grid would be impacted.
63
A lot of bad stuff would happen, to put it mildly.
64
The good news is that we have a solution now to this future problem.
65
In fact, a lot of people have been working on this space for a decade already. In 2024.
66
That work culminated in the U .S.
67
National Institute of Standards and Technology, also known as NIST, coming out with four finalist algorithms,
68
and these four are designed to be quantum -safe cryptography, or also known as post -quantum cryptography.
69
And the experts believe that these will be resistant to cracking by future quantum computers.
70
While IBM has been working hard to bring the benefits of quantum computing to the world, We're also working hard to mitigate the risk to crypto as
71
three of those four finalist algorithms actually had IBM contributors working on them.
72
And we hired a person who worked on the fourth.
73
So we have people who understand this space.
74
And we've also contributed these algorithms to the open source community
75
so that everyone can benefit from these and use these to make our systems safe.
76
But that's not the end of the story.
77
In order for there to be a happy ending, you have to actually implement these new standards in your systems.
78
That's not going to be easy since some organizations have literally thousands of applications
79
that leverage cryptography that will need to be updated.
80
In order to do this, you're going to need people,
81
process, and technology all working together to transform to this post -quantum era.
82
And because of the harvest now decrypt later situation I mentioned before, you need to actually start on this, well, yesterday.
83
So remember that time machine that I mentioned?
84
That's going to come in handy because all you have to do is build one of those, go back in time, re -encrypt all your data with these new algorithms, and you're set.
85
Well, okay, until the time machine technology is perfected, here's what you actually can do now.
86
The goal here is this thing we call crypto agility.
87
In other words, I want to future -proof my cryptographic implementations.
88
So that if we have to make changes again in the future, I don't have a brittle system that I have to go back and do all this pain again with.
89
That I can just snap something else in and continue going.
90
And we're going to need some tools in order to get there.
91
Oh, and the great thing here that I need to underscore is
92
that you don't need a quantum computer to use quantum cryptography.
93
All the tools and algorithms that will make you quantum safe run on today's classical computers.
94
So, we'll take that technology, and what we then need to do is apply these steps.
95
Discover, manage, and remediate.
96
So let's start with the discovery part of this.
97
And NIST gives us some guidance.
98
They have said organizations should create a cryptographic inventory that offers visibility into how the organization leverages cryptography.
99
That sounds like sound advice to me.
100
So what that means is if I'm going to create that inventory, I need a way to find it.
101
And if you try to do it manually, I guarantee you'll miss some.
102
So what you want to do is have a system that has some automated scanning capability, where it goes and looks across your source code,
103
it looks across the network, and it looks for all implementations of cryptography in your environment.
104
There was one major bank that when they did this type of exercise,
105
they found that they had more than 4 ,000 applications with cryptography built into them.
106
That's a lot.
107
Stop and think for just a second.
108
If they did a conversion, a migration of every one of those, let's say they could do one a day, that actually would be pretty aggressive.
109
If they did one a day, how long is it going to take them to get to full blown crypto agility and crypto safe, quantum safe?
110
The number is more than 10 years.
111
So this is why, again, the problem is a now problem that we have to start working on.
112
We can't wait for the future on this.
113
And then once you've done that, another thing you want to take a look at is if I know where all of this stuff is, I want to find out where the vulnerable crypto is.
114
Probably it's most of it today, but I'm going to create that list and catalog what kinds of algorithms are being used in each one of these cases.
115
And then ultimately the goal is to create this thing, a C -bomb, a cryptographic bill of materials.
116
That's where we're going to have this whole list that we've now discovered.
117
And now with that, we can move into the next step.
118
The next step involves managing all of this.
119
And with the management, I'm going to start with policy.
120
So I need to spell out as an organization, in other words, define what is our crypto policy.
121
What What levels of strength do we need?
122
What kinds of things need to be encrypted?
123
What kinds of things need to be done?
124
That sort of thing.
125
And I want to be able to do some enforcement of whatever that policy is.
126
Ultimately, this is a massive project.
127
Again if we're talking 4 ,000 implementations and yours might be smaller but it's still going to be a large project, I need to also figure out what are the priorities.
128
I need to prioritize each one of these, and then once I've picked out, because since I can't do all of them at once, pick the ones that are the most impactful,
129
that have the most sensitive information in them, and then go after those.
130
Then I need to track the results of all of this.
131
This is a massive multi -year project.
132
I need to see where I am, in fact, on this journey, because it is, in fact, going to be a journey.
133
Then we start moving into the remediation phase.
134
This is where we're going to start moving from our classical crypto into the quantum safe crypto or the post quantum
135
post quantum crypto PQC That's the stuff that we ultimately are trying to get to Well,
136
if I can't convert all of these things in an instant I can't just snap my fingers and make it happen.
137
What could I do in order to get there?
138
Well one thing that would give some level of protection today would be to use a proxy
139
crypto proxy that sits in and does some of this conversion for me.
140
Now here's how it would work.
141
Let's say we have a user who out here is on a browser and their browser, let's say it's already been updated to be crypto safe.
142
It's using one of these new algorithms, but our back -end legacy app over here has not.
143
In fact, we might be afraid to even crack this thing open
144
because we don't know how many lines of code are in there
145
and they were written a million years ago and all that kind of thing.
146
But we can't afford, this has got keys to the kingdom, we can't afford just to have it vulnerable.
147
So what I could do is stand up a proxy in the middle.
148
This proxy would be communicating, it understands the quantum safe crypto algorithms.
149
So it's doing quantum safe crypto between the browser and the proxy,
150
and then the proxy continues with the normal classical algorithms back to the backend application.
151
So that way, we at least encrypt, if this is the part that's over the public network, we at least have strengthened that part without having to make changes to the back end.
152
And this part all maintains within our very private network where the risk is lower.
153
So that's an important capability that allows us to move at least
154
while we're in the migration phase and be able to tolerate and work with these new algorithms.
155
Another thing that we're going to want to do is test the performance.
156
So, these algorithms, we believe, are going to be highly performant, but it all depends on the individual implementation that you're using.
157
And if you have a poor implementation, well, you might end up in a mess.
158
So what we need to be able to do is make sure we have something that works well.
159
And you want to be able to test and make sure that those things work.
160
You can't go back in time to prevent past cases of harvesting of your encrypted data,
161
But you can start now on the path to crypto agility with the right people process
162
and technology You can mitigate the risk of harvest now decrypt later at least until you build that time machine
📺 نفس القناة
✨ فيديو موصى به
حول هذا الدرس
أنت تتدرب على اللغة الإنجليزية باستخدام "Crypto Agility Explained: Protect Data from Quantum Computing Threats" مع تقنية الـ Shadowing.
ما هي تقنية التظليل الصوتي؟
التظليل الصوتي (Shadowing) تقنية تعلم لغة مدعومة علمياً، طُورت أصلاً لتدريب المترجمين الفوريين المحترفين. الطريقة بسيطة لكنها قوية: تستمع لصوت إنجليزي أصلي وتكرره فوراً بصوت عالٍ — كظل يتبع المتحدث بتأخير 1-2 ثانية. تُظهر الأبحاث تحسناً كبيراً في دقة النطق والتنغيم والإيقاع وربط الأصوات والاستماع والطلاقة.












