YY
Yasir Yakup Demircan
— On the schedule —
Investigating cryptography deployments in security-certified products with sec-certs
What can we find out about the utilization of cryptographic libraries in security-certified software and devices? Who uses what library? What additional information can you discover without having to sign an NDA? Security certification schemes like Common Criteria (CC) and FIPS 140 help users identify what IT products are secure, yet there are gaps between the formal certification documents publicly available and the actual makeup of the product ecosystem. We will share a new extensive data-driven analysis to address this deficiency, utilizing our sec-certs framework (https://sec-certs.org/). And focusing mainly on the usage of the most commonly used cryptographic libraries. Approximately 23-25% of all new certificates issued in the last ten years mention OpenSSL, making it a major player. Followed by Network Security Services (NSS), BoringSSL, and Libgcrypt. Our data exposes distinct vendor strategies and highlights significant patch lags in forks like BoringSSL across certified products. Furthermore, by mapping the lifecycle of critical cryptographic weaknesses like DUAL_EC_DRBG, X9.31 PRNG, and hardcoded keys, we reveal how insecure configurations persist within the ecosystem. There are many additional findings of interest, underscoring the necessity for more comprehensive and organized reporting of software components in security certifications.
— Compositor's note —
Yasir is a PhD student at Masaryk University who explores the intersection of automated data science and security standardization. He leverages machine learning to scrutinize the efficacy of CC and FIPS 140 certifications, uncovering systemic security gaps in the protocols that protect our most sensitive data.