A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Software Security Cryptography - Aaron Bedra (Central Ohio Infosec Summit 2015) (Hacking Illustrated Series InfoSec Tutorial Videos)

Software Security Cryptography
Aaron Bedra

OWASP/App Sec - Session #1 - Aaron Bedra Following close on the heels of heartbleed we have seen a resurgence in questioning C as the implementation choice for critical infrastructure. With performance innovations on managed runtimes the option to implement more and more critical pieces in alternative languages is becoming tangible. Of course this brings along with it a different set of problems. To re-write a system like OpenSSL or even just to implement SSL/TLS on top of a managed runtime there are some serious obstacles to overcome. This talk will examine solving the memory management problem present when building cryptographic systems on top of managed runtimes. It's no secret that key material and other such sensitive data should be able to be properly allocated and erased from memory with certainty. Aaron will detail the problem with a small implementation of a common cryptographic system and demonstrate how the issue surfaces. He will then detail what steps need to be taken to solve this issue and re-examine the suitability of using these platforms for critical infrastructure.

Bio: Aaron is a Principal Engineer at Groupon. He is the creator of Repsheet, an open source threat intelligence and attack prevention framework. He is the co-author of Programming Clojure, 2nd Edition, and a frequent open source contributor.

Back to Central Ohio Infosec Summit 2015 video list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast