In Root we Trust Pavan Chander Lisa Bui OWASP Toronto: Feb 20, - - PowerPoint PPT Presentation

in root we trust
SMART_READER_LITE
LIVE PREVIEW

In Root we Trust Pavan Chander Lisa Bui OWASP Toronto: Feb 20, - - PowerPoint PPT Presentation

In Root we Trust Pavan Chander Lisa Bui OWASP Toronto: Feb 20, 2019 Who are we? Pavan Chander Lisa Bui pchander@deloitte.ca libui@deloitte.ca Pavan is a Manager with Deloittes Lisa is a consultant in Deloittes Risk Cyber Risk


slide-1
SLIDE 1

In Root we Trust

Pavan Chander Lisa Bui

OWASP Toronto: Feb 20, 2019

slide-2
SLIDE 2

Who are we?

Pavan Chander pchander@deloitte.ca Pavan is a Manager with Deloitte’s Cyber Risk Advisory practice and has led WebTrust assurance engagements of both public and enterprise CAs. He has also been an

  • fficial witness to several root key

generation ceremonies both in Canada and internationally. Lisa Bui libui@deloitte.ca Lisa is a consultant in Deloitte’s Risk Advisory practice. Her specialties include trust considerations of Public Key Infrastructure, Cyber Security, Enterprise Risk, and Third Party Service Auditor Reporting.

slide-3
SLIDE 3
slide-4
SLIDE 4

Let’s talk about encryption

slide-5
SLIDE 5
slide-6
SLIDE 6

Symmetric encryption

slide-7
SLIDE 7

Asymmetric encryption

slide-8
SLIDE 8

1993 2019

slide-9
SLIDE 9

Subject: google.ca Validity period: Feb 1, 2019 to Feb 28, 2019 Usage: Server authentication

slide-10
SLIDE 10
slide-11
SLIDE 11

Certification Authorities

Amazon, Comodo, DigiCert, Entrust, GoDaddy, Google, Symantec, VeriSign, and many more...

slide-12
SLIDE 12
slide-13
SLIDE 13
slide-14
SLIDE 14
slide-15
SLIDE 15

Industry: CA/Browser Forum

  • Certification Authorities
  • Browser/OS vendors

(e.g. Apple, Google, Microsoft, Mozilla) Auditors: CPA Canada WebTrust/PKI Assurance Taskforce

  • CPA Canada members
  • Audit firms
slide-16
SLIDE 16

Other things...

  • Publicly trusted vs Enterprise
  • Other use cases

○ Client authentication: VPN ○ Code signing: Airplanes, Windows Updates ○ Email ○ V2X

slide-17
SLIDE 17
slide-18
SLIDE 18
slide-19
SLIDE 19

Microsoft trust store

Governments of…

  • Australia
  • Brazil
  • Finland
  • France
  • Hong Kong
  • Hungary
  • India
  • Japan
  • Korea
  • Lithuania
  • Macao
  • Portugal
  • Saudi Arabia
  • Slovenia
  • South Africa
  • Spain
  • Sweden
  • Taiwan
  • The Netherlands
  • Tunisia
  • Turkey
  • Uruguay

...plus many private sector companies from around the world

slide-20
SLIDE 20

Takeaways...

  • https://cabforum.org/
  • http://www.webtrust.org/
  • https://wiki.mozilla.org/CA
  • https://groups.google.com/forum/#

!forum/mozilla.dev.security.policy

  • https://crt.sh/?cablint=1+week
slide-21
SLIDE 21