Explore the significant changes in ESAPI 2.0 Crypto in this 16-minute conference talk by Kevin Wall, ESAPI Project co-owner, at LASCON 2012. Learn about the reasons behind the crypto changes, the problems with ECB mode, and the importance of message authenticity. Gain insights into padding oracle attacks and examine advanced crypto examples. Discover how these updates enhance enterprise security and improve cryptographic implementations in ESAPI 2.0.
Overview
Syllabus
Intro
Obligatory CV
Why the ESAPI 2.0 Crypto Changes?
What's Wrong with ECB Mode?
Why Do We Need Message Authenticity?
Aside: Padding Oracle Attack
Major Changes in ESAPI 2.0 Crypto
Advanced Crypto Example (cont'd)
Taught by
LASCON