Matt Cheung - Introduction to Cryptographic Attacks

Matt Cheung - Introduction to Cryptographic Attacks

Thursday Morning DEF CON Workshop Starting at 0900 PDT

By DEF CON WORKSHOPS

Date and time

Thursday, August 10, 2023 · 9am - 1pm PDT

Location

Flamingo Las Vegas

3555 South Las Vegas Boulevard Las Vegas, NV 89109

About this event

Max Class Size: 30

Abstract:

Using cryptography is often a subtle practice and mistakes can result in significant vulnerabilities. This workshop will cover many of these vulnerabilities which have shown up in the real world, including CVE-2020-0601. This will be a hands-on workshop where you will implement the attacks after each one is explained. I will provide a VM with Python dependencies and skeleton code included so you can focus on implementing the attack. A good way to determine if this workshop is for you is to look at the challenges at cryptopals.com and see if those look interesting, but you could use in person help understanding the attacks. While not a strict subset of those challenges, there is significant overlap. Participants should have VMWare, VirtualBox, or some other VM software installed.

Skill Level: Beginner to Intermediate

Prerequisites for students: Students should be comfortable with modular arithmetic and the properties of XOR. Experience in Python or other similar language will be a plus.

Materials or Equipment students will need to bring to participate: A laptop with VMWare or VirtualBox installed and capable of running a VM.

Bio:

Matt Cheung started developing his interest in cryptography during an internship in 2011. He worked on implementation of a secure multi-party protocol by adding elliptic curve support to an existing secure text pattern matching protocol. Implementation weaknesses were not a priority and this concerned Matt. This concern prompted him to learn about cryptographic attacks from Dan Boneh's crypto 1 course offered on Coursera and the Matasano/cryptopals challenges. From this experience he has given workshops at the Boston Application Security Conference, BSidesLV, DEF CON, and the Crypto and Privacy Village.

Organized by

DEF CON Workshops are an opportunity to learn from others in our community in a four hour class. The workshops range in difficulty from n00b to hardcore hacker and on almost any topic that you can think of in the realm of hacking.

Now on to some things to keep in mind while you look at which workshop(s) to register for:

Workshop Registration will be handled online. Announcement will be made as we get ready to open reg the day before.

In order to decrease the number of no-shows, DEF CON Workshops will be instituting a $25 registration fee to attendees. Tickets are available on a first come, first served basis. Additional costs include possible low-fee for material costs, if applicable, and will be collected by the instructor at the time of the workshop.

There will be a limited number of students on standby lists for each class, should a registration cancel.

There will be NO onsite registration, period. Anyone on standby will be notified they are on standby before the conference. There will be NO onsite standby line or list to sign up for. Everything will be arranged pre-con.

Students will be limited to purchasing 2 tickets per class.

You can register for as many classes as you can attend in one day. ( No two classes at the same time. If you have mastered occupying two spaces at the same time, there are some physics academics who would be pleased to meet you among others)

Sales Ended