The program will open the story of Alexander Kostinsky and Sergey Smirnov about the digital signature. The microphone has Alexander Kostinsky.
Kostinsky
In May, we talked about the use on the Internet to encrypt e -mail by a publicly accessible, persistent PGP cryptographic program. At the end of the program, another important tool was briefly mentioned - a digital signature that is necessary to control the integrity of the correspondence, and in particular, for conducting electronic business. Today's program is devoted to a more detailed consideration of this most important element of e -commerce.
Using a persistent cryptography, you can not only hide your letter from curious eyes. Using the programs similar PGP, you will always know that the letter has come intact, and it was not replaced on the road. For this, a digital signature is just used. By its purpose, it is similar to the usual one, which is put on paper documents. By such a signature, you can make sure that the letter is written precisely by you, and not someone else. PGP allows you to sign your message with several clicks. How is this done?
To begin with, recall the main points of encryption with an open key. In the beginning, the program automatically creates two keys used exclusively in pairs. An open key can be sent by mail to friends, placed on the network, sent to the local department of the FSB. With this key, acquaintances will encrypt the messages to your address, but after that they will no longer be able to decipher their own message to you, since the open key can only encrypt. Only you can read the letters, the owner of a paired secret key. In the case of digital signature, the opposite is true. You sign a message using a secret key, and anyone who you will send or who is not too lazy to download your open key from a database on the Internet can verify the authorship of the document. The degree of protection of the digital signature from the fake is as high as the degree of resistance during encryption using PGP.
Some listeners probably have a thought: why, if it is very necessary, not copy a digital signature from a genuine document and “stick” to another? This is sometimes received with messages sent by fax, for example, payment orders. But with the digital signature PGP will not work. The fact is that it contains not only data about the "owner", but also in a special way compiled digest, that is, the summary of the document itself. If the attacker sees the letter and makes changes to it, then as a result of checking the first line of the message instead of “good” you will see “BAD”. A sure sign that someone had a hand in the letter while the messenger was resting on the way in a roadside camp.
As you have already guessed, encryption and electronic signature can be successfully applied together. First you sign the document with your secret key, and then encrypt an open key to the addressee. The signature certifies the identity, encryption protects the letter from prying eyes.
But, the digital signature is used, of course, not only (and not so much) for friendly correspondence. It allows you to conclude transactions at a distance and exchange digital money with partners that you do not know and, perhaps, do not really trust them. Digital signature with date and time is important for the media, legal organizations, and special services. With its help, you can confirm the originality of photographs, sound and video recordings - all that, with modern digital processing methods, is so easy to change. Without a digital signature, all transactions on the Internet will slow down, because people will have to certify their intentions using conventional means of communication.
In mass mail programs, for example, Outlook Express, there is also an option of digital signature - “Digital ID”. True, in PGP you are free to create the keys yourself and change them at least every hour. In Outlook Express, the keys will have to receive the keys in Verisign, Inc., which is strongly recommended by Microsoft. At first, you will be given to practice for free, but Verisign is not a charitable organization. They will periodically check the authenticity of information about you and take money for it. Microsoft, Unfortunately, does not explain how Verisign will check the non-Americans.
This is already a well -known scheme with depositing keys. The scheme, as we see, is not very attractive for private correspondence. Someone unknown will keep in your pocket copies of your keys. What he will do with them, you are unlikely to find out. Since Microsoft agrees to the resistance of its ciphers with FAPSI, as was the case when starting Windows-2000, this system cannot be called quite reliable. Fortunately, the keys mandatory for citizens go out of fashion in the legislation of the countries of the world. But, despite this, it must be emphasized that for e -commerce, the key depositing scheme is mandatory. It is necessary, in order to avoid fakes, so that some service confirms that this signature belongs to this particular organization. Usually, such a service, like a notary public, certifies the signature of the organization with its electronic signature.
In Russia, however, as of July 2000, the digital signature has no legal force. Having come to the court with such "evidence", you can only hope for sympathy and understanding of the chairman. And if the opposite side declares that he did not hear about the document or the signature, the judge may well agree with her. Today, in our country, a bill on an electronic digital signature is being developed. This is the rare case when almost all interested parties agree with the need to adopt the law. According to the project, it is supposed to create a certification center (or centers) for storing open keys and confirming their belonging to the authors. Such centers will act on the basis of a state license. For everyone who will apply to this service center with the corresponding request, a certificate for a specific key will be issued. According to the certificate, it will be possible to unequivocally determine who this key belongs. The bill allows the use of electronic digital signature as evidence in court. It is expected that the project will be submitted for discussion in the parliament by the Russian government.
But still, how reliable is the electronic signature if such a majority of trade operations will rely on it? Consider the main concerns about the security signature, implemented by an open key encryption scheme collected in the article by Ilya Ivta and Vadim Bogdanov "Is there a digital signature?"
They quite rightly say: "Electronic signature is not at all a signature in the proper sense of the word, but the composition of complex information and technical manipulations. With all its desire, an organic subject can not" turn "in a virtual electronic space in any future, consisting entirely of units and zeros."
Again, correctly and Bogdanov draws attention to the fact that the mathematical algorithm for encryption with an open key, which underlies electronic signature technology, is fundamentally vulnerable. More precisely, however, there would be no strict evidence of the invulnerability of such algorithms. The decomposition of very large numbers into simple multipliers, integer logarithming is now carried out by overcoming options. With a sufficient value of key numbers over reasonable time, it is not feasible to overcome options. But if an algorithm of an effective solution of such problems is found, then decoating almost all messages will immediately become possible. In our opinion, the danger is somewhat exaggerated, since the task of decomposing the number on simple multipliers has already been set two thousand years ago and so far there are no encouraging approaches to its solution. This, of course, does not mean that such approaches cannot be found. However, the experience of studying such "great tasks" shows that their solution cannot be found suddenly a brilliant loner. It is enough to recall how painfully the Great Farm Theorem was painfully proved. A new branch of the theory of numbers should be created, if not all mathematics, which in several large jumps is suitable for such a problem. Moreover, it is very likely that many experts will see the approach of the denouement and will be able to warn the community about this.
Another vulnerable point of the encryption system with open keys to IVT and Bogdanov consider the imperfect mechanism for identifying the real sender of the message. Getting data encrypted with an open key - paired to secret or secret - paired to open, you can be sure that when successful decryption, these keys are really from one pair, but how can you make sure that during the first shipment you were not intercepted on the road and was not replaced by an attacker’s open key to which he just has a paired secret key? It is assumed that the open key is sent together with the message in one letter or until the letter itself, but the recipient cannot find its replacement.
Such a danger really exists, but civilian cryptographs have long realized it and offered several ways to overcome it. The PGP provides for these purposes that for important cases, the signature of new members of the community is assured by those whose keys are definitely not false and the recipient and recipient know about this. In addition, immediately after generating a new pair of keys, it is proposed to send an open key to an accessible database on the network. Then the addressee takes the key to there, and he is real. You can avoid a more exotic case when an attacker goes even further: intercepts an open key along the road or break off the open key database and put his dummy key under the same name. But the prevention of such actions is not very complicated. Before sending an important message, the sender must check whether the open key in the database under his name is a pair of the secret key that he has stored. To do this, he just needs to encrypt any text with a suspicious open key and immediately deciphered with his paired secret. If this fails, then it is highly likely that the key is fake. And only after such an audit, he offers the addressee to take his open key from the Internet. But how to confirm that the “good” itself for correspondence is not fake, that he was not intercepted either? Of course, the way out of this situation implies contacts between people outside the Internet and checking information on parallel channels. But this is exactly what happens in real business and legal practice. And not one serious contract is not concluded without personal contacts of at least some team members. During these meetings, important signatures and open keys are checked, since it takes several minutes. It can be argued that in this way critical data is focused in one person and become vulnerable. But here we concern more general safety problems.
It is impossible to consider the protection of digital communications is isolated and it is considered only a certain mathematical task, where the ideal demon easily replaces all messages. You can hack any protection. Eugene Spiford on this occasion said: "Only a system that is turned off, walled up in a concrete corps, locked in a room with lead walls and is protected by an armed guard, but in this case, no doubts leave me, can be considered." A practically important question is how much time will require time and money. Is it difficult to fake ordinary documents with the current development of computer processing of images, scanners and laser printers? And a very realistic polymer seal is inexpensive to make almost at home. Classic fake methods are much cheaper than hacking computer networks with constant tracking and targeted replacement of messages with false ones.
Certification systems via the Internet also have weaknesses, but the usual notary, on whose honesty, many transactions depend, is in collusion with criminals and certifies non -existent documents. Despite this, the institution of notaries exists and is developing. Is it possible to compare the security of our apartments and cars with bank safes? Despite this, the metal door is better than wooden, the lattices on the windows have not only psychological significance, and it is still better not to put the keys to the apartment under the rug or in the distribution panel of electric communication on the floor. At each barrier, attackers are worthy, and they should be more professional. Do not forget that the network of interbank international Swift payments has long been working for a long time, electronic bank cards are widespread, although there are often cases of fake and theft in banking machines.
So it is difficult to agree with the categorical opinion of Ivt and Bogdanov that "electronic signatures have no future." It seems to us that the well -known cryptographer Adi Shamir, who has been working for a long time and well -known practical achievements of Israeli special services: “Absolutely safe systems, does not exist and will never exist. Most importantly, do not try to achieve perfect security communications, because this leads to a weakening of overall security. Strong computer cryptography is usually not hacked, therefore it is treated. Cryptography is not enough, because it is already the most powerful link in a single system of security of the system. "
Radio "Freedom", the program "Seventh Continent". In conclusion - Mikhail Kretschmer about the future of the press.
Krechmer
Many and many forecasts are devoted to the Internet. Sometimes they are similar to reality, sometimes - to the pages of a fantastic novel or scanning. For many people today, probably, genetic engineering - cloning and the Internet are seen by the most fantastic. And not so long ago, the Internet and genetic engineering met in a completely unexpected place - at the pig farm.
One of the five pigs that were born in the spring due to cloning in the American city of Blaxberg (Virginia) was called a bonnom. There is no this word in English, as not, probably in any other. A pig from the test tube was called the name of the extensions, which end with many addresses known to us in the World Wide Web. In Russian, it sounds like a “lump point”, in English - “pillbox”, and abbreviated - dott. She was named after the Internet and its achievements.
Forecasts, forecasts: in order to find out the past, people turn to historians. To find out the present - to journalists. In order to find out the future, our people usually ask questions to astrologers and futurologists. Less commonly - researchers and analysts. We will turn to one of the last numbers of the journal "Quill". It is published by the American society of professional journalists, QUILL translated from English means "goose pen." So the QUILL magazine shares the forecasts about what fate the Internet prepares to journalists, as well as all of us - readers of the press.
Researcher David Cole claims that the near future did not dream of any futurologists. Contrary to leisure, we will be printed in the future in the future. But this is only one of the possible ways to deliver newspapers. Along with this, the market will confidently conquer the online newspapers, or, as it is customary to say now, the network press. Twenty -four hours a day, information in such publications will be updated seven days a week. And these publications can fundamentally change the relationship between the reader and the publisher.
At all times, the publisher dictated his will to readers: "You get a newspaper only after we decided to print it." In fact, you can wait for the postman in the morning, stand in line in the line for a newspaper kiosk or pick up mail from a newspaper box in the evening. But no one can pick up a fresh newspaper earlier than the typographic machines are heated at the time (according to the publisher) time. Should the reader suffer from the fact that he wanted to read fresh news at 3 a.m., at 9 in the morning or at 9 pm? Now the reader dictates his conditions for news producers. He enters the Internet and looks at the most fresh information to this minute.
Another solution to the problem is the device for the "pocket" Internet - mini -computer. They are produced today by many well -known companies. They are always at hand and can continuously receive information and give it to their owners. Another thing is that the work is added to the creators of the news: the format of these devices and special software requires that the information comes to them different from the one that is intended for ordinary personal computers.
It seems that this is inevitable: the desktop and pocket network press will develop along with the improvement of the quality of the image and sound. But since the habit of reading news from the paper sheet will not disappear soon, but the book -like displays and electronic paper will be prepared for a long time, then the temptation will remain a network newspaper. To do this, it will be enough to place a pack of paper in a device similar to a microwave oven and press a button. Perhaps this will be the virtual end of the printing press.
But with all technological innovations, the essence of journalistic labor is unlikely to change a lot. По-прежнему необходимо будет уметь хорошо писать, уметь просто объяснять сложные вещи, отделять главное от второстепенного. И много чего еще уметь. Новые технологии, приборы и аппараты не заменят труд журналиста, они дают новые инструменты людям этой профессии. И инструменты будут непрерывно совершенствоваться.
Эксперт в области компьютерной журналистики Дженифер Лефлер утверждает, что никто сегодня уже не говорит о журналистах, использующих компьютер просто для набивания текстов. Вот как может выглядеть журналист и его работа в ближайшем будущем. Ручки и блокноты будут заменены цифровыми записывающими устройствами. Речи, интервью, собственные комментарии, начитанные на пленку, будут сразу выдаваться в виде печатного текста. Миниатюрные профессиональные видеокамеры позволят легко выполнять качественную цифровую видеозапись и фотосъемку событий. При необходимости все эти аудио, видео и текстовые файлы могут быть сразу отправлены в редакцию при помощи переносного компьютера и Интернета.
Интересно, каким может быть следующий этап работы. Придя с задания, журналист, прежде всего, напишет небольшой, в 50 слов репортаж для миниатюрных карманных компьютеров и отошлет его потребителю. После этого напишет расширенный, слов в 200 материал для обычного Веб-сайта и разместит его там, попутно выбрав и разместив необходимые аудио и видеофайлы. И только после этого сядет за работу над большим "кирпичом" в тысячу слов для печатной версии газеты. А тут подоспеет время обновить репортаж для карманных, а потом и настольных компьютеров.
На самом деле, ничего фантастического в этом нет. Более того, кое-где уже так работают: в Bloomberg News, Orlando Sentinel, Chicago Tribune. Пока используемый лишь в нескольких компаниях, этот способ подачи и передачи новостей будет все больше и больше развиваться.
What happens? Получается, что газетная журналистика может обрести вид непрерывной трансляции, постоянно обновляющихся текстов и заголовков. Можно сказать, наступит новая эра телетайпной журналистики.
Если вести речь о конкуренции, хорошей работе и хорошем заработке, то большое преимущество будут иметь те журналисты, которые знают новую технику и новые технологии и смогут пользоваться ими лучше других. Так что газетная журналистика постепенно из гуманитарной профессии превращается в очень даже техническую. И если еще не физика и лирика, то лирика и кибернетика - уж точно могут стать родными.
А мне осталось поблагодарить Джеймса Грея - исполнительного директора американского Общества профессиональных журналистов за помощь в подготовке материала.
All links in the text of the programs lead to the pages of persons and organizations not related to the Radio "Freedom"; The editors are not responsible for the content of these pages.