SAN FRANCISCO — It’s impossible to escape the shadow of the coronavirus at this year’s RSA cybersecurity mega event. From the marquee cancellations (IBM, AT&T, and Verizon, among others) to the ubiquitous hand sanitizer dispensers in Moscone Center, and techies who seem to relish unironically fist bumping ad nauseam, it’s top of mind — and a frequent topic of discussion.
Today’s keynotes were no exception starting with RSA President Rohit Ghai’s cautionary tale about Typhoid Mary — “an excellent cook who did not wash her hands,” — and thus spread typhoid.
Up next on the keynote stage, McAfee CTO Steve Grobman made a more direct connection between cybersecurity and the coronavirus. “We decided to use the flu as a metaphor for cybersecurity way back in December, clearly not knowing that the coronavirus would impact friends and colleagues around the world.”
From Coronavirus …Grobman’s keynote made the case that existing cyberdefenses share too many traits with legacy immunology practices. “The point being that infectious disease requires a spectrum of action from sophisticated technology to fundamental, simple basic principles like, as you just heard, washing hands,” he said. “Consider the challenges of some of the most fundamental principles in our world. Are we being aggressive enough in the way that we share threat intelligence? No. We must move beyond the hash and move to higher fidelity threat sharing paradigms.”
And, to make the connection between Ghai’s Typhoid Mary example and cybersecurity: “consider the people who cook the food rather than those who consume it,” with the cooks being the software developers, serving up delicious, and sometimes vulnerability-ridden code to end users.
“For far too long we have failed to hold IT and software makers accountable for cyber hygiene and vulnerabilities. … We need to continue to educate the users, but it is time to invite IT to our story as primary characters acting as the first line of defense.”
To Cybersecurity and QuantumCloud computing gives business access to new technologies, but it also brings new cloud-specific risks and enlarges the threat landscape, Grobman said. One of these promising technologies is quantum-as-a-service. “But for our industry as with cloud, we know that quantum is a double-edged sword,” he added. Quantum computing can enable breakthroughs in biology, chemistry, and physics. On the flip side, nation states can use quantum to break public key cryptosystems.
“Now I know what many of you are thinking: Quantum is not coming anytime soon. But we can’t think of quantum in terms of eventually or tomorrow,” Grobman said. “Because quantum is a real risk today, you must assume that adversaries are already accessing your most sensitive data. It’s encrypted, but they still find it valuable. They’re not worried about encrypting it today, they’re counting on quantum to do that in the future.”
Over 70% of all traffic is encrypted and it travels over an untrusted network — the public internet. So criminals and nation states can syphon that data today and then use quantum to unlock it in the future. Why does it matter it attackers can unlock today’s data five or even 15 years from now? “Even in 2020, documents in the National Archives related to the Kennedy assassination, nearly 60 years ago, still retain redactions for current national security concerns,” Grobman said.
Addressing this problem requires public and private sectors to work together — and a massive funding infusion, he argued. The U.S. government’s quantum research budget, to address a national security issue, is $30 million, or just 0.0006% of the federal budget.
“We need quantum resistant algorithms as soon as possible,” Grobman said. “This is already doing amazing work, but we must help them move faster. They require more funding.”
And it’s very difficult to select the right algorithm. Of the initial 69 algorithms proposed, 12 were broken or attacked in three weeks, Grobman said. Three years later, “we still only narrowed the rest of the field to 26.”
In the more immediate future, Grobman called on all of the RSA Conference attendees to move their network traffic to TLS 1.3 protocol, which provides massively improved privacy and performance benefits compared to earlier version of TLS and non-secure HTTP.
“And while that won’t prevent the traffic from being decrypted by quantum at some point, it does make it significantly more difficult for an attacker to execute at scale,” he said. “Finally together, government and industry has much to do in partnership. Let’s pledge to start the technical work beyond just the mathematical algorithms. To inventory, understand, and retool all of the systems that are based on quantum-vulnerable attacks. Whether it’s driving changes through IETF to support a post-quantum TLS, or testing new ecosystems for quantum secure code signing capabilities, we must begin today.”
Comments