Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Def Con – We should move away from PKI says Zimmermann

by The Gurus
August 9, 2014
in Editor's News
Share on FacebookShare on Twitter

We need pervasive encryption as the public key infrastructure (PKI) is generally “a bad idea” and something we should move away from.
 
According to cryptographer Phil Zimmermann, we need a new form of pervasive encryption and we need to create pervasive crypto and cause a legislative environment to push back and make a change. Speaking at the Def Con event in Las Vegas, Zimmermann said that the crypto wars were won in the 1990s as “we got everyone to participate in a public policy debate and we we won and we got the export controls back”, and said “we can do the same thing here”.
 
Speaking on the rollout of his new venture Silent Circle, he made the analogy that in the United States in the 19th century, people would not eat tomatoes as it was assumed that they were poisonous, and now phone companies think that they cannot break away from the culture of wiretapping and surveillance. “The CISO of Dutch telecommunications provider KPN has been working with us and want to offer their customers real privacy so pople can call and whisper in each others ears without anyone intercepting the conversation,” he said. “I hope other phone companies will follow suit and others are talking to us about doing the same thing.”
 
He admitted that the decision to offer secure communications was partly influenced by surveillance revelation by Edward Snowden, and also by a demand for change, while phone companies feel the market pressure of users. “Soon it will be possible to whisper in ears from 1000 miles away and that will be the new normal,” he said.
 
Asked why he felt strong encryption was not used ubiqutously,.Zimmermann said it was necessary to understand how it works and understand what it mans to have persistent public and private keys, but we do not worry about that with phone calls. “With calls you don’t need PKI as generally a bad idea and you can use common sense to see if they match and if they do not, there is a wiretapper,” he said.
 
Referring to the Comodo Hacker who hacked into the certificate authority DigiNotar and gave certificates to the Iranian government, Zimmermann said it was “hard to imagine a more spectacular failure of PKI than that”, and said that even if you were writing fiction, “it is hard to concoct a more spectacular indictment of PKI than that”.
 
Zimmermann said that in the 1990s we fought in the “crypto wars” andhad to justify using strong crypto, but fast forward to today in the legislative environment where have to justify yourself if you are NOT using strong crypto.
 
He said: If you leave a laptop with 200,000 records on the disc, you better hope it is encrypted, or you have to go public and announce you lost 200,000 names. I don’t see people using strong crypto; we fought for it in 1990s and cannot fight back, after 9/11 I thought it would be rolled back but it was not, and then Attorney General John Ashcroft did not remove it either.”

ShareTweet
Previous Post

ICO warns lawyers over data protection

Next Post

Blackphone rooted at Def Con

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol