VM
Vashek Matyas
— On the schedule —
Investigating cryptography deployments in security-certified products with sec-certs
What can we find out about the utilization of cryptographic libraries in security-certified software and devices? Who uses what library? What additional information can you discover without having to sign an NDA? Security certification schemes like Common Criteria (CC) and FIPS 140 help users identify what IT products are secure, yet there are gaps between the formal certification documents publicly available and the actual makeup of the product ecosystem. We will share a new extensive data-driven analysis to address this deficiency, utilizing our sec-certs framework (https://sec-certs.org/). And focusing mainly on the usage of the most commonly used cryptographic libraries. Approximately 23-25% of all new certificates issued in the last ten years mention OpenSSL, making it a major player. Followed by Network Security Services (NSS), BoringSSL, and Libgcrypt. Our data exposes distinct vendor strategies and highlights significant patch lags in forks like BoringSSL across certified products. Furthermore, by mapping the lifecycle of critical cryptographic weaknesses like DUAL_EC_DRBG, X9.31 PRNG, and hardcoded keys, we reveal how insecure configurations persist within the ecosystem. There are many additional findings of interest, underscoring the necessity for more comprehensive and organized reporting of software components in security certifications.
— Compositor's note —
Vashek (Václav) Matyáš is a Professor at Masaryk University, Brno, heading its Centre for Research on Cryptography and Security. His research interests relate to applied cryptography and security; with over 200 peer-reviewed papers and articles. He worked also with Cybernetica, Red Hat Czech, CyLab at Carnegie Mellon University, as a Fulbright-Masaryk Visiting Scholar at Harvard University, Microsoft Research Cambridge, University College Dublin, Ubilab at UBS AG, and as a Royal Society Postdoctoral Fellow with the Cambridge University Computer Lab. Vashek also worked on the Common Criteria and in ISO/IEC JTC1 SC27.