Not Your Keys, Not Your Name

CDC Mini Stage
CDC
This talk will explain the benefits of decentralized protocols which use public keys *directly* as identities, and encourage this approach for newly-designed protocols.
Speaker: F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E0 (also known as Adam Joseph) This talk will explain the benefits of decentralized protocols which use public keys *directly* as identities, and encourage this approach for newly-designed protocols. The example familiar to the most CCC attendees is Tor [onion names](http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion). At least [20 other protocols use this strategy](https://codeberg.org/amjoseph/not-your-keys-not-your-name) as well. This talk will briefly survey those examples and explain the benefits of this approach for *autonomy*, *decentralization*, and *ability to resist surveillance*. The main alternative to public keys is names controlled by some globally trusted party, such as US-ICANN, the DNSSEC root key, or the browser-vendors\' WebPKI appointees. This talk will explain the drawbacks of centralized alternatives.\r\n\r\nIf a protocol uses public keys as identities, it should allow users to keep their permanent private key offline. Private keys in *online* "secure elements" are not offline. Because an online device requires a network connection its physical location cannot be hidden; this means it can be seized or stolen and the keys extracted using a vulnerability like [the one recently discovered in all Yubikeys and Infineon TPMs](https://eprint.iacr.org/2024/1380). Only a small number of protocols support offline identity keys. This support cannot be added to a protocol "after the fact"; it must be included from the very beginning. This talk will encourage protocol designers to include this feature from the very beginning, and will give concrete advice ("copy SSH or Tor") on how to do it. More details can be found here: [https://codeberg.org/amjoseph/not-your-keys-not-your-name](https://codeberg.org/amjoseph/not-your-keys-not-your-name).

Additional information

Type other
Language English

More sessions

12/27/24
HouseOfTea
House of Tea
Come and join our warm, cozy -cafeinated and non-cafeinated- journey/conspiracy!
12/27/24
iblech
EmbracingHackingOHPs
How a mathematical breakthrough made at the end of the 17th century is the workhorse of the artificial neural networks of today
12/27/24
SoS Saal 6
[More information in the Angelsystem](https://engel.events.ccc.de/news/11)
12/27/24
liv (she/her)
SoS Saal D
If you are neurodivergent or looked into the topics ADHD and Autism this might be the session for you. Unsure? No worries. Curiosity is enough to participate. I'll bring some fidget toys, talk a little about stimming and accessibility for neurodivergent minds. Please bring your own topics, life-hacks and toys so we can learn from each other! *CN:* Attendees might want to raise topics that can be triggering. These can be discussed in smaller groups where everyone is okay with it.
12/27/24
elzbeth
Kidspace - Basteltische
Telefonarmbänder aus waschbarer Pappe selbermachen
12/27/24
elzbeth
Kidspace - Workshopraum
Ein Awareness-Team für den Kidspace - wer macht mit?
12/27/24
CDC
CDC Pentagon
This is a monero-beginner-friendly workshop for nerds, bring your computer to follow along and by the end you will have a monero wallet in your terminal and understand how to use it.