{
    "componentChunkName": "component---src-templates-about-blog-template-js",
    "path": "/blogs/chinese-researchers-rsa-is-breakable-others-do-not-panic",
    "result": {"data":{"blog":{"content":"**Quantum computing not only poses a great opportunity, but also a great threat to internet security. According to the promises of quantum computers, certain mathematical problems that form the basis of today’s most popular cryptographic algorithms will be much easier to solve with them than with classical computers. In a recent publication, Chinese researchers claim that there is an existing algorithm that, even with today's quantum computers, makes it possible to break the RSA algorithm, which is the fundamental basis of secure internet communication. At the same time, there are doubts about the reliability of the publication. However, even if these doubts are confirmed, it does not change the fact that the security threat posed by quantum computers remains with us.**\n\nThe basic claim of the [paper](https://arxiv.org/pdf/2212.12372.pdf), published last Christmas by 24 Chinese researchers, is that they have found an algorithm that enables 2,048-bit RSA keys to be broken even with the relatively low-power quantum computers available today. There is nothing really new in the fact that quantum computers pose a general risk to the reliability of cryptographic procedures that guarantee secure internet communications, such as [RSA open-key cryptography](https://en.wikipedia.org/wiki/RSA_(cryptosystem)) or the Diffie-Hellman key exchange algorithm. These procedures are based on mathematical problems that are practically unsolvable with conventional computers, but which can be solved in a few hours with sufficiently powerful quantum computers. Sufficiently large means 20 million [quantum bits](https://en.wikipedia.org/wiki/Qubit) (qubit) in this case. The problem with this figure of 20 million is that <span style=\"text-decoration:underline;\">IBM's quantum computer</span> – the largest quantum computer known today – can only render 433 of these 20 million qubits. It is not an exaggeration to say that the Chinese researchers chose one of the steepest hills to climb. But can they really overcome this challenge?\n\n> [Integer factorization](https://en.wikipedia.org/wiki/Integer_factorization) is the most widely used infeasible mathematical problem to guarantee that the cryptographic algorithms are practically unbreakable. Factorizing a number consisting of only a few digits is trivial (15 = 3 * 5), but the required computational capacity grows exponentially along with the number of digits. For hundreds or even thousands of digits, the computational effort required is so enormous that even using the highest performance supercomputers, the time required to do the calculation would be similar to the lifetime of the universe. According to the [recommendation](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf) of the [National Institute of Standards and Technology](https://en.wikipedia.org/wiki/National_Institute_of_Standards_and_Technology) (NIST), the smallest RSA key size that can be considered secure is 2,048 bits. This means approximately 600 digits, but in many cases larger keys of 3,072 or 4,096 bits are also used. There, the number of digits expressed in the decimal number system already exceeds a thousand, meaning that these keys are practically infeasible with traditional methods. At the same time, in 1994<span style=\"text-decoration:underline;\"> [Peter Shor](https://en.wikipedia.org/wiki/Peter_Shor)</span> already came up with an [algorithm](https://en.wikipedia.org/wiki/Shor%27s_algorithm) that – on a quantum computer only existing in theory at the time – would be able to perform the prime factorization with much greater efficiency than before. This breakthrough would imply that a significant part of our encryption procedures would no longer be resistant to breaking, including, among other things, HTTPS, which ensures the security of browsing, or VPN protocols, one of the foundations of remote work.\n\n## Has Cryptographic Apocalypse Now arrived?\n\nThe Chinese researchers could only provide a theoretical answer to this question, since the solution and the techniques outlined by them require a 372-qubit computer. Though this does exist within the walls of IBM,  the Chinese researchers did not have this machine at their disposal. However, they did succeed in factoring a 48-bit (15-digit) number with a 10-qubit computer. At first sight, this may not seem like much of a breakthrough, but it should be noted that this is the largest number that has ever been factored using a generic algorithm. Not to mention the fact that it was possible to put a theory into practice. The question is whether it was possible to bridge the aforementioned gap. As the correspondence between [Bruce Schneier](https://en.wikipedia.org/wiki/Bruce_Schneier) – one of the iconic figures of IT security – and [Roger A. Grimes](https://www.amazon.com/stores/Roger-A.-Grimes/author/B001IQUMT4) – the author of several books on cryptography – revealed:\n\n>“Apparently what happened is another guy who had previously announced he was able to break traditional asymmetric encryption using classical computers…but reviewers found a flaw in his algorithm and that guy had to retract his paper. But this Chinese team realized that the step that killed the whole thing could be solved by small quantum computers. So they tested and it worked.”\n\nYou might think that the cryptographic apocalypse is here.\n\n## Keep Calm and Dig Deep\n\nThe basis of the Chinese researchers’ algorithm relies on [Claus Schnorr](https://en.wikipedia.org/wiki/Claus_P._Schnorr)'s factorization algorithm (not to be confused with [Shor’s algorithm](https://en.wikipedia.org/wiki/Shor%27s_algorithm)). The aforementioned algorithm works well with smaller numbers – with which the researchers themselves tested it – but falls apart with larger values. It is precisely this limitation that the Chinese researchers claim to have overcome. However, they do not mention any details, and they have not been able to prove the complete theory in practice due to the lack of a quantum computer with sufficient capacity. As Schneier cited the situation on his blog:\n\n> “So if it’s true that the Chinese paper depends on this Schnorr technique that doesn’t scale, the techniques in this Chinese paper won’t scale, either. (On the other hand, if it does scale then I think it also breaks a bunch of lattice-based public-key cryptosystems.)”\n\nDoes the uncertainty remain until someone tries the algorithm on a sufficiently large-capacity quantum computer? Partially.\n\nThere are, in fact, some signs that cast doubt on the whole story. One of these is that the Chinese researchers failed to win the $200,000 prize offered by the [RSA Factoring Challenge](https://en.wikipedia.org/wiki/RSA_Factoring_Challenge), which goes to whoever can successfully crack a 2048-bit RSA key. Of course, you could say that they did not have the necessary hardware, but a letter to IBM to get the prize, even if it is shared, would have been certainly worthwhile. People drawn to conspiracy theories may ask why the Chinese state did not keep the discovery for itself and started pouring money into the development of a suitable quantum computer. This would obviously cost a very substantial amount, but would also bring a very substantial benefit. At the same time, there is also strong skepticism from the scientific side. [Scott Aaronson](https://en.wikipedia.org/wiki/Scott_Aaronson) – former researcher at MIT, now at the University of Texas – made a [devastating statement on his blog](https://scottaaronson.blog/?p=6957) about the Chinese paper. Aaronson, in his pieces of research, primarily focuses on quantum computing and complexity theory, perhaps the most important fields of science concerning our topic. His three-word review about the content of the publication was: “No. Just no.” He criticized the publication in a firm tone:\n\n\n> “Then, finally, they come clean about the one crucial point in a single sentence of the Conclusion section:\n> It should be pointed out that the quantum speedup of the algorithm is unclear due to the ambiguous convergence of QAOA.\n> “Unclear” is an understatement here. It seems to me that a miracle would be required for the approach here to yield any benefit at all, compared to just running the classical Schnorr’s algorithm on your laptop. And if the latter were able to break RSA, it would’ve already done so.\n> All told, this is one of the most actively misleading quantum computing papers I’ve seen in 25 years, and I’ve seen … many.”\n\nAaronson is not alone in his opinion: [many](https://www.linkedin.com/feed/update/urn:li:activity:7016808281847336960/) [others](https://www.linkedin.com/feed/update/urn:li:activity:7017366747691241472/) criticize the research on the same basis, including Peter Shor, who says:\n\n> “There are apparently possible problems with this paper.”\n\nIt should also be highlighted that the research-sharing platform ([arχiv](https://arxiv.org/)), where the Chinese study was published, [does not perform peer reviews](https://arxiv.org/about), meaning that the mere fact of publication does not mean much, especially in such popular fields as quantum computing and cryptography. \n\n## So, are we off the hook or not?\n\nEven if we are able to recognize all the [research paper mills](https://en.wikipedia.org/wiki/Research_paper_mill) – which must necessarily be expected in a popular and highly regarded discipline such as cryptography or quantum computing –  the harsh reality remains. Any encrypted data recorded today that uses a cryptographic process that does not withstand the challenges posed by quantum computers could become compromised in the not-too-distant future. As a result, it would be necessary to use algorithms that are thought to be secure against a cryptoanalytic attack by a quantum computer to mitigate the effect of the harvest-now-decrypt-later technique, as it cannot be eliminated. In the  case of a cryptographic problem that received great publicity, such as Heartbleed in 2014, the market reacted relatively quickly, although it was weeks before the error disappeared from the 100,000 most-visited pages. In other cases, which have not received as much publicity, it can take years, according to statistics from [Qualys Pulse](https://www.ssllabs.com/ssl-pulse/) . In other words, we cannot expect the introduction of post-quantum cryptography to happen much faster than this.\n\nThis is just like global warming: a problem that cannot be dealt with in the future when it becomes critical. It should be dealt with in the present. The similarity is striking if we consider the fact that scientists have been scaring people with horror stories about quantum computers for decades. What seemed like a theory for a while, has now become the reality. [IBM promises a one-thousand-qubit computer](https://www.science.org/content/article/ibm-promises-1000-qubit-quantum-computer-milestone-2023) by the end of the year, and [Google a one-million-qubit one](https://www.cnet.com/tech/computing/google-plans-to-build-a-practical-quantum-computer-by-2029-at-new-center/) by the end of the decade. The latter does not promise anything good, since it is only a question of data storage capacity – how much data can be accessed after RSA becomes breakable. The first to have machines with sufficient capacity will presumably be the still much-criticized technology giants, and the most powerful states. Lawmakers still call for encryption backdoors [from time](https://www.helpnetsecurity.com/2017/06/20/eu-encryption-law/) [to time](https://www.helpnetsecurity.com/2021/04/05/weak-encryption/), despite the [warnings](https://balasys.eu/blogs/weakened-encryption-is-a-silver-bullet-not-just-for-law-enforcement-agencies-but-for-cybercriminals) about the [serious risks involved](https://pfeifferszilard.hu/2021/02/25/cryptography-weakening-a-tale-of-the-law-abiding-criminal.html), but with such a technical breakthrough, they would not necessarily need to do so. However, this may have consequences that are difficult to foresee both for privacy and the outcomes of conflicts that are increasingly transferred to cyberspace.","title":"Chinese researchers: RSA is breakable. Others: Do not panic! ","short_description":"In a recent publication, Chinese researchers claim that there is an existing algorithm that, even with today's quantum computers, makes it possible to break the RSA algorithm, which is the fundamental basis of secure internet communication. At the same time, there are doubts about the reliability of the publication.","author":"Szilárd Pfeiffer","date":"2023-02-20","hero":{"url":"https://balasysmediastorage.blob.core.windows.net/websiteimages/uploads/christian_lendl_Zytt_G_Su_o2_E_unsplash_76adf1b110.jpg"},"SEO":{"title":"Chinese researchers: RSA is breakable. Others: Do not panic!","isIndexable":true,"description":"In a recent publication, Chinese researchers claim that there is an existing algorithm that, even with today's quantum computers, makes it possible to break the RSA algorithm, which is the fundamental basis of secure internet communication. At the same time, there are doubts about the reliability of the publication.","keywords":"rsa, quantum computing, shor's algorithm, qubit, rsa challenge","preview":{"url":"https://balasysmediastorage.blob.core.windows.net/websiteimages/uploads/christian_lendl_Zytt_G_Su_o2_E_unsplash_76adf1b110.jpg"}}},"related":{"nodes":[{"author":"Szilárd Pfeiffer","avatar":{"url":"https://balasysmediastorage.blob.core.windows.net/websiteimages/uploads/jievani_weerasinghe_NHRM_1u4_GD_A_unsplash_5998edbcc5.jpg"},"content":"**Researchers at **[Kudelski Security](https://kudelskisecurity.com/)** have **[managed to break](https://research.kudelskisecurity.com/2023/03/06/polynonce-a-tale-of-a-novel-ecdsa-attack-and-bitcoin-tears/)** Bitcoin and Ethereum wallets using a novel attack against one of the most popular asymmetric key algorithms of modern cryptography. Although **[Satoshi Nakamoto](https://en.wikipedia.org/wiki/Satoshi_Nakamoto)**’s wallet was not among the 764 wallets they were able to break, it is quite worrying to see that a software issue can make such a modern cryptographic algorithm like ECDSA vulnerable. Analysis of data that comes purely from open sources could reveal a practical weakness of an algorithm that is the fundamental basis of secure internet communication, public key infrastructures, and cryptocurrency transactions.**\n\n\n## Software Issue Behind the Scenes\n\nAs with many other times in the history of attacks against cryptographic algorithms, the cause of a successful attack is not a vulnerability in the algorithm itself, but the fact that poor-quality software used an algorithm with insufficient care. It is crucial to obtain “high-quality” random numbers during the calculation of many cryptographic operations. Such operations store passwords using [salt](https://en.wikipedia.org/wiki/Salt_(cryptography))ed [hash](https://en.wikipedia.org/wiki/Cryptographic_hash_function)es, the generation of cryptographic keys used to authenticate web servers on the internet, or an employee before access is given to the company’s private network using a virtual private network (VPN) service. The generation of [digital signature](https://en.wikipedia.org/wiki/Digital_signature)s – which is necessary for the verification of the transactions – also requires a cryptographically strong random value. In the absence of strong random values, there would be a relation between the random and the private part of the signing key. This property could be exploited, and the private key can be acquired by an attacker. In the possession of the private key, any transaction related to the key can be verified, meaning that the balance of the wallet can be transferred.\n\n\n## Not a New Idea, but a New Method\n\nThough the attack itself is novel, the idea behind the attack is not so new. The lack of high-quality random numbers has caused serious vulnerabilities in the past. In 2002, a researcher found an [issue](https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-0166) in the version of the [OpenSSL](https://www.openssl.org/) distributed with [Debian](https://www.debian.org/) Linux and its derivatives that reduced the entropy of generated random values. The issue caused SSH, VPN, and X.509 keys generated by the affected versions of OpenSSL to become vulnerable. Services still used a key generated by the affected version of the code which meant they remained vulnerable until the regeneration of the key. In 2010, a group called _fail0verflow _compromised an ECDSA key [Sony](https://en.wikipedia.org/wiki/Sony) used to sign software for the [PlayStation 3](https://en.wikipedia.org/wiki/PlayStation_3) game console. The root cause of the attack was almost the same as it is now, namely Sony did not use different random numbers when digitally signing different software. The novelty of the current attack is that it exploits the high-degree relationships among the random values ([nonce](https://en.wikipedia.org/wiki/Cryptographic_nonce)s) used to generate digital signatures. It means if the nonce was not generated by a cryptographically secure random number generator but using a weak [pseudo-random number generator](https://en.wikipedia.org/wiki/Pseudorandom_number_generator) (PRNG), it would allow the attacker to retrieve the private part of the key used to generate the signatures.\n\n\n## Special Kind of Open-source Intelligence\n\nThree prerequisites must be met to successfully retrieve the signer’s private key from signatures. The first one is that the random value used to generate the signature should come from a weak PRNG. The second one is to have a batch of consecutive digital signatures generated by using the same PRNG. The third one is that the signatures can be ordered, meaning that we know which signatures have been generated after which one. It could be assumed that there are implementations that use weak PRNGs as it is not basic knowledge whether random number generators are adequate for cryptographic purposes and some legacy software may follow older guidelines. The question is: where can an attacker find a consecutive and ordered list of signatures? The answer is: in several places. Digital signatures are part of each cryptographic protocol, so they can be collected from open sources. The best examples are [cryptocurrencies](https://en.wikipedia.org/wiki/Cryptocurrency), where the transfers are validated by digital signatures. These digital signatures must be published to allow each party to validate the transactions. Basically, cryptocurrency [blockchain](https://en.wikipedia.org/wiki/Blockchain)s are huge collections of the necessary signatures. For instance, researchers could collect 763 million unique signatures from the Bitcoin blockchain which were generated by 424 million unique public keys. Most of the time a key was used to generate only a few signatures, but millions of keys generated at least four signatures, which is the minimum requirement of the attack.\n\n\n## Someone Got Ahead of the Researchers\n\nResearchers ran their attack for two days and 19 hours with an estimated cost of USD 265, resulting in 762 unique broken wallets, but someone may have gotten ahead of them, as all the wallets had zero balance. The researchers suspect that these wallets have already been hacked in the past. If they had not been hacked, 484 BTC could have been stolen from these wallets, which means almost 12 million USD. However, 484 BTC was worth 31 million USD at Bitcoin’s peak. The question arises, where did the money go? The researchers obtained that the recipients were addressed by the latest transactions of the broken wallets. They identified 466 different recipient addresses, where the top 1 received 75 BTC, and the top 5 received 140 BTC, meaning more than USD 1.5 million, and almost USD 3 million, respectively. They counted 144 BTC in total, which is far from the theoretical 484 BTC, but it still sounds like a profitable business, worth the aforementioned USD 265 cost of the investigation. After the first transaction to the top address in 2018, several transactions were initiated from that address to several recipients for 0.5 or 1 BTC, although the account still had a balance of 63.5 BTC. Researchers also found public conversations about accounts that were swept exploiting repeated nonces. A forum member called _johoe_ [claimed](https://bitcointalk.org/index.php?topic=1431060.0) that he had collected 135 addresses that can be compromised using that technique, and 82 had been compromised already at the time of his post. He also stated that he collected 7 BTC from the broken accounts. He was willing to send the funds back to the owner after proving ownership. The researchers repeated their attack against Ethereum after collecting more than 1.7 billion ECDSA signatures. They managed to break 2 unique wallets processing 22% of their signature collection. They decided to stop the attack, considering that the cost-benefit ratio was too low.\n\n\n## Is This Still a Real Issue Now?\n\nConsidering only the results related to the Bitcoin wallets, I would say this might not be an issue anymore. The exploitable signatures were generated several years ago, perhaps with the same software that had a serious flaw, which may have already been fixed. The signatures were exploitable not because they used a pseudo-random generator during signature generation, but due to repeated nonce values. At the same time, given that digital signatures are used in so many cases, such as during a cryptographic handshake, this may still be a significant issue. Exploiting the vulnerability indeed requires getting consecutive signatures from a potentially affected server, which is not a trivial problem in the case of a busy server, as many other clients connect to a server between our consecutive connections. Even so, if an attacker manages to exploit a server, the server certificate is compromised without any sign on the server. For as much as the [certificate revocation is one of the weakest points of X.509](https://pfeifferszilard.hu/2020/09/09/why-do-certificate-revocation-checking-mechanisms-never-work.html), it is troubling that such a simple flow in an implementation can cause certificate compromise. The case would be even more worrying if there were a similar flow in certificate issuance, as this would compromise a CA, which could result in unpredictable consequences.\n\nPhoto by[ Jievani Weerasinghe](https://unsplash.com/@jievani?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText) on[ Unsplash](https://unsplash.com/photos/NHRM1u4GD_A?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText)\n","date":"2023-03-16","id":"Blogposts_36","short_description":"Researchers at Kudelski Security have managed to break Bitcoin and Ethereum wallets using a novel attack against one of the most popular asymmetric key algorithms of modern cryptography, ECDSA.","slug":"bitcoin-account-hijacking-ecdsa-nonce-break","title":"Bitcoin account hijacking using OSINT techniques"},{"author":"László Horváth, Pre-Sales Engineer at Balasys","avatar":{"url":"https://balasysmediastorage.blob.core.windows.net/websiteimages/uploads/code_1839406_1280_48de8cd8f8.jpg"},"content":"*WAF-as-a-service solutions are becoming an increasingly popular method for protecting websites and services running in the cloud. One significant advantage is the vendors' claim that security settings can be updated in time based on the data from incoming attacks that are caught. However, the question arises: how effective and inevitable are current WAFs and WAF-as-a-service solutions?*\n\nIt is essential to address this issue as injection attacks are a prominent feature in the periodic OWASP Top 10 list, ranking 1st in 2013 and 2017 and 3rd in 2021, after broken access control and cryptographic failures. \n\n\n## Autospear: the new generation of SQL attacks \n\nAt the Black Hat Asia conference in May, researchers from Zhejiang University in China presented a new automated SQLi method for testing and bypassing signature-based WAFs. The method consists of using algorithms to modify the code originally intended to be injected – which is detected and blocked by firewalls by default – until it cannot be detected using the negative security model. \n\nThe modifications were as follows: \n\n| MODIFICATION  | EXAMPLE  |\n| ---  | ---  |\n| Case Swapping  | or 1 = 1 → oR 1 = 1  |\n| Whitespace Substitution  | or 1 = 1 → \\tor1\\n=1  |\n| Comment Injection  | or 1 = 1 → /\\*foo\\*/or 1 =/\\*bar\\*/1  |\n| Comment Rewriting  | /\\*foo\\*/or 1 = 1 → /\\*1.png\\*/or 1 = 1  |\n| Integer Encoding  | or 1 = 1 → or 0x1 = 1  |\n| Operator Swapping  | or 1 = 1 → or 1 like 1  |\n| Logical Invariant  | or 1 = 1 → or 1 = 1 and 'a' = 'a'  |\n| Inline Comment  | or 1 = 1 → /\\*!or/ 1 = 1<br>union select → /\\*!union\\*/ /\\*!50000select\\*/  |\n| Where Rewriting  | where xxx → where xxx and True<br>where xxx → where (select 0) or xxx  |\n| DML Substitution  | or 1 = 1 → \\|\\| 1 = 1 <br>and name = 'foo‘ → && name = 'foo'  |\n| Tautology Substitution  | 1 = 1 → ‘foo’ = ‘foo’<br>‘1’ = ‘1‘ → 2 <> 3 <br>1 = 1 → (select ord(’r’) regexp 114) = 0x1  |\n\nThe point of the modifications, in this case, is that the SQL command will not change semantically, and the database server will be able to process it, but the signature-based protection can be bypassed. To do this, an algorithm is used that systematically maps which modifications can be run by trial and error and uses the feedback to design the code for the final attack. \n\nThe researchers tested the method on seven popular web application firewalls, four of which are available on Amazon Web Services as WAF-as-a-service. They focused on four types of requests (GET / GET(JSON) / POST / POST(JSON) and generated 10,000 unique codes from 100 known SQLi expressions. \n\nThe results suggest that WAF-as-a-service solutions can be attacked with high effectiveness, as there were vendors with 89% or more success using JSON payload. \n \n\n## Positive security model: protection against Autospear and other attacks\n\nThe positive security model has often been criticized for being more time-consuming and complex – and therefore more costly – to develop than the signature-based model. Still, it can provide much more effective protection against Autospear and similar attacks. With a properly designed and maintained API schema, the acceptable incoming data in a given field can be limited to the point where any modification that does not contain the expected data will immediately block the call. For example, in a userid field, you can specify precisely where and what characters are expected, their length, and composition. \n\nThis takes time and expertise, and needs to be tailored to the specific API in each case. It is not a switch that, when flipped, can give a false sense of security that you are protected against OWASP Top10 vulnerabilities. \n\nAnother severe criticism is that the positive security model gives too many false positives, though this problem can be avoided using expert-created and maintained templates and continuous feedback during testing. \n\nHowever, a proper API security solution can help you to build your positive security model effectively. It is essential to ensure proper logging is in place during the development and testing phase. This can help you picture what your core traffic consists of and what vulnerabilities exist. A positive security model also enables you to test existing – or possibly missing – traffic-based schemes under controlled conditions. You can provide appropriate feedback to your developers by filtering out any calls that may occur that do not conform to the scheme. This can be recorded in log files in a developer environment with accurate feedback without interrupting the call. In a live system, you can immediately cut off the call without feedback or send a misleading message to the attacker. ","date":"2022-11-30","id":"Blogposts_33","short_description":"Web Application Firewalls (WAFs) are widely used to protect websites and APIs against various attacks, such as SQL injection (SQLi) and cross-site-scripting (XSS). ","slug":"weaknesses-of-signature-based-api-protection","title":"Weaknesses of signature-based API protection"},{"author":"Szilárd Pfeiffer, Security Engineer & Evangelist, Balasys","avatar":{"url":"https://balasysmediastorage.blob.core.windows.net/websiteimages/uploads/ZT_Blog_balasys_6349a385158f9_1405296b55.jpg"},"content":"The Cybersecurity Tech Accord, throughout Cybersecurity Awareness Month in October, broke down the core elements of “Zero Trust” architecture in a blog series – Never Trust, Always Verify. The series featured expert voices from across Cybersecurity Tech Accord signatories analyzing what Zero Trust is, what is isn’t, and how to have an informed conversation to ensure your organization is employing best practices for security.\n\nSzilárd Pfeiffer, Security Engineer & Evangelist at Balasys, wrote about Zero Trust and strong authentication.\n\n### What is Zero Trust and why is it important?\n\nTraditional cybersecurity approaches focus on establishing a sound perimeter to keep malicious actors outside a network. This assumes that all users and resources inside the perimeter are trustworthy. In today’s world, however, resources are increasingly hybrid in their structure, and data are spread across an innumerable combination of devices, services, applications, and people. This makes security more complicated than simply keeping bad actors outside a network; good security means knowing more about who’s inside as well.  According to the Zero Trust Architecture’s principle guideline – never trust, always verify – no resource should be accessed until successful authentication and authorization have been achieved.\n\nWhile the Zero Trust security Model was first introduced in the 1990’s, it’s only become widely known and used in the past few years because, like many things, it is far easier said than done. But one thing is for sure: the improved security environment is worth the effort, and it begins with strong authentication. The Zero Trust security model is an approach to the design and implementation of information technology systems. The main concept behind the architecture is de-perimeterization, which refers to the removal of a boundary between an organization and the outside world.\n\n### The seven tenets of Zero Trust\n\nThe United States’ Cybersecurity and Infrastructure Security Agency (CISA) [has outlined the following principles](https://www.cisa.gov/sites/default/files/publications/CISA%20Zero%20Trust%20Maturity%20Model_Draft.pdf) in its Zero Trust Maturity Model:\n\n**1. All data sources and computing services are considered resources.**\n\nEven if the network is composed of multiple classes of devices, this tenant does not allow exceptions. In practice, there should be at least one policy enforcement point in the network where all the traffic goes through and where the policy can be enforced.\n\n**2. All communication is secured regardless of network location.**\n\nSecure communication and providing trust are no longer based on the location of an asset.\n\n**3. Access to individual enterprise resources is granted on a per-session basis.**\n\nAn evaluation should be made before giving access to a resource independently of whether the resource was previously permitted or not.\n\n**4. Access to resources is determined by dynamic policy.**\n\nThe policies should be generated as real time as possible and should always be appropriate to the attributes.\n\n**5. The enterprise monitors and measures the integrity and security posture of all owned and associated assets.**\n\nNo asset should inherently be trusted, and data integrity should be maintained at all times.\n\n**6. All resource authentications and authorizations are dynamic and strictly enforced before access is allowed.**\n\nAuthentication and authorization should always be rigorously checked at each access request before access is granted to a resource.\n\n**7. The enterprise collects as much information as possible about the current state of assets, network infrastructure, and communications, and uses this information to improve its security posture.**\n\nMaintaining and improving security posture is a never-ending circle: collecting and analyzing data are essential to the process.\n\nWhile there is no one definition for Zero Trust architecture, the major tenets of the approach, as described by CISA, make clear that strong authentication is at its foundation. And strong authentication needs to be a priority for all security architecture, as password issues are responsible for more than 80 percent of data breaches. And strong passwords alone are not enough. Organizations today require more robust protections to defend themselves against the latest threats. Though  more and more companies are investing in various strong/multifactor authentication methods, it has proven easier to purchase a solution than to effectively implement and introduce it across an organization. So how should organizations start to actually follow through in adopting strong authentication practices?\n\n\n## ALWAYS ENCRYPT AND ALWAYS ENCRYPT WELL\nThe ‘zeroth’ step in implementing strong authentication is reliable encryption. Zero Trust requires that enterprises never consider their private network as an implicit zone of trust. Assets on a network should always be handled as if an attacker was persistent on the system. As a result, access to resources should be granted in the most secure manner available. This entails not just authenticating all connections, but also encrypting all the traffic. Attackers are smart, and capable enough to eavesdrop on a network, analyze any unencrypted traffic to capture credentials to perform a well-structured attack later.\n\nIn the case of a private network or service, it is good practice to allow only the most secure cryptographic algorithms that provides [forward secrecy](https://en.wikipedia.org/wiki/Forward_secrecy), such as [ECDHE](https://en.wikipedia.org/wiki/Elliptic-curve_Diffie%E2%80%93Hellman) and [authenticated encryption](https://en.wikipedia.org/wiki/Authenticated_encryption), such as [Poly1305](https://en.wikipedia.org/wiki/Poly1305). Attacker toolchains – such as other software systems – often contain legacy parts that do not support the most modern mechanisms. This means that an exploit used against a service that can be accessed solely via encrypted channels, using the most modern algorithms, will fail before it can really begin, even if the attacker can access the system and has valid credentials, as the initiation of the encrypted connection will fail. This approach also has other indirect benefits. Using state-of-the-art encryption increases security as connection failure events can be reported as suspicious behaviors as part of “real-time monitoring,” another requirement of Zero Trust. Beyond this, advanced encryption also helps us identify our own legacy or “shadow” systems that cannot support the most modern forms of encryption, meaning they should either be accessed through a middleware device or be sunset altogether.\n\n\n## AUTHENTICATION IS ABOUT IDENTITY, NOT METHODS\nJust like there is no reliable authentication without encryption, there is no authorization without reliable authentication. Zero Trust requires strictly enforced authentication and authorization before resource access. Unfortunately, security experts sometimes focus on methods instead of identity. Passwords, certificates, tokens, or biometrics are just methods, they are not the identity itself.\n\nFor instance, spyware can collect login credentials by harvesting from the databases of pawned sites, especially when users use their company email addresses for private purposes. Meanwhile, simpler passwords can be brute-forced to be discovered. If security is compromised, the password can no longer prove identity.  You might think that a more modern and sophisticated method – such as a digital certificate – could solve the issue of simple passwords, but at the end of the day the strength of the certificates depends on the strength of the password that protects the certificate’s private key. If an attacker can compromise a protecting password, the authentication based on the certificate is also compromised.\n\n[Multi-factor authentication](https://en.wikipedia.org/wiki/Multi-factor_authentication) (MFA, or 2FA) has not become so popular for nothing, and security experts today encourage both individuals and companies to use at least a second factor in authentication. However, MFA also has weak points in addition to its significant benefits. A typical [time-based, one-time password](https://en.wikipedia.org/wiki/Time-based_one-time_password) (TOTP) either expires after a minute or is used as part of successful authentication. This means that even if an attacker acquires the actual value, it cannot be used for subsequent authentications. Unfortunately, this does not protect against [website spoofing](https://en.wikipedia.org/wiki/Website_spoofing), which can prompt a user to provide both their password and the TOTP on the spoofed authentication form. Using the intercepted credentials, the attacker can then authenticate in the name of the victim.\n\nA more convenient, but less secure, second factor in MFA is [“push-based” authentication](https://en.wikipedia.org/wiki/Multi-factor_authentication#Mobile_phone-based_authentication) where, following a successful password-based authentication, the user confirms the login by clicking “Yes, it was me” in a push notification received on their mobile device. However, if an attacker can compromise the password, several login attempts can be made that cause several push notifications on the mobile device of the victim. Just one confirmation in error that occurs either accidentally or through getting tired of the spoofing [(MFA fatigue attack)](https://www.securityweek.com/high-profile-hacks-show-effectiveness-mfa-fatigue-attacks) is enough for the attacker to get into the system. It is also important to remember that a mobile-based second factor cannot be any more secure than the protection of the mobile device itself. If the mobile device isn’t locked, we risk the sense of the second factor, and this is the case if confirmation can be done without unlocking, or the locking pattern is simple, [predictable](https://arstechnica.com/information-technology/2015/08/new-data-uncovers-the-surprising-predictability-of-android-lock-patterns/), or vulnerable to [smudge attack](https://en.wikipedia.org/wiki/Smudge_attack).\n\nTo make a long story short: MFA is an essential best practice, but no matter how perfect a solution may seem, security awareness is still essential.\n\n\n## AUTHENTICATION IS NECESSARY, BUT NOT SUFFICIENT\nZero Trust Network Architecture requires both encryption and authentication, but these are means, not an end in and of themselves. According to the [National Institute of Standards and Technology (NIST) in a special publication on Zero Trust architecture](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf), both authentication and authorization should be strictly enforced every time before access is granted to any resources inside or outside of the private network, in line with the [principle of least privilege](https://en.wikipedia.org/wiki/Principle_of_least_privilege). This means that the classification of a resource should also vary the conditions of the resource access. Depending on the observable state of client identity, the requesting assets, or other behavioral and environmental attributes, various levels of access can be granted for a resource.\n\nThe principle of least privilege (PoLP), also known as the principle of minimal privilege (PoMP) or the principle of least authority (PoLA), requires that in a particular abstraction layer of a computing environment, every module (such as a process, a user, or a program, depending on the subject) must be able to access only the information and resources that are necessary for its legitimate purpose.\n\nFor instance, under certain circumstances, strictly “read-only” access may be granted to a particular resource, but upon further authentication “read-write” access can be provided as well. The situation reflects approaches to physical security, where entering physical environments with higher classification requires additional authentication. In terms of network and data security, access to data should mirror physical security considerations and authentication requirements for access to a location. In this dynamic, authentication is not just a single step – pass through the doors and you’re in – but rather a repeatedly executed task of the policy enforcement process based on what is being accessed and how.\n\nThe first tenet of Zero Trust says that all computing services are considered resources. Authentication services should be considered as resources, meaning that access should be granted taking the least privilege principle into account. It means that the number of authentication requests, including successful and unsuccessful, should not exceed a certain number. Rate limiting unsuccessful authentication requests helps to prevent brute-force attacks against the first factor of the authentication, such as a password. However, this does not diminish the importance of choosing properly secure passwords. Rate limiting successful authentication requests helps to avoid the compromise of the second factor after the first factor has already been compromised. For instance, an MFA fatigue attack is hardly feasible if the number of successful authentication requests is limited. Zero Trust requires monitoring and measuring the security posture of all owned and associated assets, meaning that exceeding the rate limit should be monitored and could trigger the deactivation of a user account that is suspected to be compromised. This is how identity handling becomes dynamic, something which is required at the optimal level of maturity in the [Zero Trust Maturity Model](https://www.cisa.gov/sites/default/files/publications/CISA%20Zero%20Trust%20Maturity%20Model_Draft.pdf).\n\n\n## HUMAN FACTOR IS UNAVOIDABLE IN AUTHENTICATION\nWhile trying to achieve the higher and higher levels of Zero Trust maturity, we should not forget about the weakest link in all security system chains: humans. Security is often contrary to comfort, yet discomfort is usually also contrary to security. Even the trendiest, most cutting-edge , methods can have weak points that attackers can successfully exploit while the most traditional methods might work effectively under such circumstances. Not surprisingly, users tend to bypass security systems if the discomfort they experience exceeds a certain level. Bothering users with [frequent password changes](https://learn.microsoft.com/en-us/archive/blogs/secguide/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903) is a particularly good example of this. Users who are forced to frequently change their passwords often fall into two kinds of bad habits for security when trying to remember their passwords. The first is writing it down where others can see it, and therefore steal it. The second is that making memorable but predictable alterations to their existing password to fulfill the password policy requirements.\n\nA conventional authentication method such as a password can be secure, but its security level does not depend on the expiry period. – rather, it depends on the entropy. The easier it is for a user to remember a strong password, the likelier it is they will use it. Security is about minimizing risks that cannot be taken without cooperation. High security requirements are good, but followable security rules that are in line with the risk are the best.\n\nThis article was originally published on the [Cybersecurity Tech Accord blog](https://cybertechaccord.org/strong-authentication-no-zero-trust-network-without-strong-authentication/). ","date":"2022-11-03","id":"Blogposts_32","short_description":"A “Zero Trust” cybersecurity model has been one of the most important innovations in organizational risk management in recent years. It constitutes a fundamental shift in mitigating risk, but one that is still not widely adopted or even understood.","slug":"no-zero-trust-network-without-strong-authentication","title":"No Zero Trust Network without strong authentication"}]}},"pageContext":{"slug":"chinese-researchers-rsa-is-breakable-others-do-not-panic"}},
    "staticQueryHashes": ["3233329270","3621970722","521397250","585144119"]}