Black Hat Europe
December 4-7, 2017
London UK
Black Hat Asia
March 20-23, 2018
Singapore
Black Hat USA
August 4-9, 2018
Las Vegas, NV, USA
11/6/2017
12:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat Europe 2017:
Deep Dive Into Crypto Vulnerabilities

Thoroughly addressing security concerns requires a combination of technical and social approaches. Using cryptographic techniques to encrypt data through complex algorithms is an essential component of any security program. Understand the role of encryption in security architecture and develop in-demand skills with the following Black Hat Europe 2017 Trainings, Briefings and Arsenal open-source tools.

 

Crypto Attacks and Defenses imparts foundational knowledge in identification and elimination of cryptographic vulnerabilities. In this two day course, students will master the latest challenges and approaches, including elliptic-curve, quantum, post-quantum cryptography and more. Begin with a basic understanding of Python, public-key and secret-key cryptography, leave with profound comprehension of cryptographic software implementations. Gain actionable experience through hands-on training using real-world secure messaging and blockchain systems.

Key Reinstallation Attacks: Breaking the WPA2 Protocol details protocol-level weaknesses in the Wi-Fi Protected Access II (WPA2) security protocol that allow key reinstallation (KRACK) attacks. The protocol-level location fundamentally impacts standard implementations affecting personal and enterprise networks. Researchers share results of tests highlighting multiple unique attack vectors for accessing secure data and compromising connected systems. Every single Wi-Fi device is susceptible to this form of attack.

Fed Up Getting Shattered and Log Jammed? A New Generation of Crypto is Coming explores modern algorithms and standardized functions derived out of them. Researchers also introduce two cryptographic protocols created out of SHA-3: Strobe, a symmetric traffic protection protocol and Disco, a TLS like protocol and library. SHA-3 lends its core cryptographic functionalities, including simplifying logic, reducing code size and increasing capabilities (hashing, generating random numbers, deriving keys, and more).

By-design Backdooring of Encryption System - Can We Trust Foreign Encryption Algorithms dissects the BEA-1, block cipher algorithm made public in 2017. Similar to the AES, BEA-1 contains a mathematical backdoor enabling an operational and effective cryptanalysis. Mathematical backdoors can be completely public yet remain inaccessible and challenging. Hear how BEA-1 was developed and learn new concepts for designing complex, undetectable backdoors.

Thalos - Simple and Secure Approach to Storage in Untrusted Environments encrypts files and prohibits decryption regardless of physical or virtual server access. Files are protected by unique cryptographic algorithms yet accessible on multiple devices. A master key and public key create a Master Key Pair which encrypts the user basefile. See a live demonstration at Black Hat Europe 2017 Arsenal on Wednesday, December 6.

Enhance your cryptography skills and more at Black Hat Europe, held at ExCeL London, December 4-7, 2017.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Want Your Daughter to Succeed in Cyber? Call Her John
John De Santis, CEO, HyTrust,  5/16/2018
Don't Roll the Dice When Prioritizing Vulnerability Fixes
Ericka Chickowski, Contributing Writer, Dark Reading,  5/15/2018
Why Enterprises Can't Ignore Third-Party IoT-Related Risks
Charlie Miller, Senior Vice President, The Santa Fe Group,  5/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Security through obscurity"
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11232
PUBLISHED: 2018-05-18
The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrectly used as a local variable.
CVE-2017-15855
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, the camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides in u...
CVE-2018-3567
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WLAN while processing the HTT_T2H_MSG_TYPE_PEER_MAP or HTT_T2H_MSG_TYPE_PEER_UNMAP messages.
CVE-2018-3568
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, in __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur.
CVE-2018-5827
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WLAN while processing an extscan hotlist event.