Sie sind auf Seite 1von 4

F EBRUARY 2017, N O 6

Cryptacus Newsletter

February’17 Cryptacus Newsletter


Welcome to the latest edition of the monthly
Cryptacus.eu newsletter, bringing you a glimpse
into recent developments in the IoT cryptanal-
ysis area. We’d love to receive more of your
contributions, comments & feedback at crypta-
cus.newsletter@irisa.fr

News from the Chair PhD Students and Postdocs are es- do not hesitate to directly contact
by G ILDAS AVOINE pecially (but not exclusively) invited Milena.
to submit a presentation proposal.
Gildas
Note that, for each selected pre-
sentation, the travel and accommo- Recommended reading
dation expenses of the speaker will
be fully reimbursed. This is an op-
portunity for young researchers to
present their work and share ideas
with researchers from the scientific
Dear Cryptacus Members, community.

I would like to start this newslet- Last but not least, the submission
ter by thanking Milena Djukanovic, process is very lightweight, given that We will briefly cover in this is-
the organizer of the Cryptacus work- only a 1-page abstract is required by sue two papers co-authored by the
shop that will take place next month the program committee for the selec- legendary Adi Shamir, investigating
in Montenegro, on March 14th-15th. tion of the presentations. Smart Lights in quite some depth.

Milena already did a great job so Whether or not you plan to sub- The first is “Extended Functional-
far to set up the workshop in a very mit a presentation, you can regis- ity Attacks on IoT Devices: The Case
short time. I am sure we will have ter to the workshop using this link: of Smart Lights”, and is authored by
a great and enjoyable event in Suto- https://goo.gl/P5eCgN. Eyal Ronen and Adi Shamir, both
more next month. from the Weizmann Institute of Sci-
Note that booking in the hotel ence.
A call for presentations was re- of the workshop is particularly con-
cently distributed around. It can venient, because Milena Djukanovic They showed how the intended
be downloaded from the Cryptacus negociated that the room rate will functionality of smart lights can be
website, at https://goo.gl/n8iyLB. include the transportation from/to abused to build a covert LIFI com-
May I ask you to distribute this call the airport and the lunches. munication system to exfiltrate data,
to relevant mailing lists? even from highly secure environ-
If you have other questions, ments. They implemented the attack

Cryptacus Newsletter
m Cryptacus.eu B cryptacus.newsletter@irisa.fr Page 1
and were able to read the leaked data This research has been covered in a but most of them apparently are go-
from a distance of over 100 meters number of major generalist newspa- ing for the straightforward topics
using only cheap and readily avail- pers and news sites such as the New of homomorphic encryption, ultra-
able equipment. Particularly funny York Times, Forbes, Motherboard, PC lightweight crypto, physical crypt-
was the fact that, as a receiver, they Magazine, The Register, Computer- analysis, quantum and automated
used a 12in Meade LX200 telescope. World, etc. proof techniques.
This was an Invited paper to IEEE
S&P Europe 2016. These brilliant papers will defi- It is possible, however, that there
You can read it at https://goo.gl/ nitely contribute to validate Shamir’s will be room for a proposal targeting
LJCM0A 15 predictions for the next 15 years, the challenge defined by ’Authenti-
as presented in his anniversary cated encrypted token research for
keynote "Financial Cryptography: mobile payment solutions and re-
Past, Present, and Future" at Fi- lated applications’. If you have ex-
nancial Cryptography 2016 (check perience in H2020, are willing to
https://goo.gl/ifBptN) particu- coordinate a proposal and have ideas
larly prediction #1 (Cybersecurity is for seriously contributing to this chal-
terrible, and will get worse) and #2 lenge, please do not hesitate to con-
(The Internet of Things will be a se- tact me at jch27@kent.ac.uk to fur-
curity disaster). ther discuss a joint bid.

Alex Biryukov’s team (Cryptolux,


at University of Luxembourg) is also
The second extremely interesting looking for partners in Crypto, Cy-
paper, on a closely related topic, is berSecurity and FinTech areas for
“IoT Goes Nuclear: Creating a ZigBee this April call, but also for some
Chain Reaction”, also authored by of the later August ones. We will
Eyal Ronen and Adi Shamir, this time be targeting DS-07-2017 on ’Ad-
with the help of Colin O’Flynn and dressing Advanced Cyber Security
Achi-Or Weingarten. Threats and Threat Actors’ https:
//goo.gl/V0Qqmd, so please drop me
I was fortunate enough to at- a line if you think you can signifi-
tend Shamir’s fantastic presenta- cantly contribute to a proposal on
tion of this work at ESC’17 in that topic.
Canach, Luxembourg. You can read
more about it at https://eprint. Of course, we will arrange in the
iacr.org/2016/1047 but I would next Cryptacus meeting in Montene-
highly recommend you to in ad- gro for a slot to discuss some of these
dition visit the awesome site de- calls in detail and will plan ahead
voted to this line of research by Eyal Funding News for them, focusing particularly on the
at http://iotworm.eyalro.net/ August calls as by them the April one
where you can find videos of them will be too close. Our aim is to fa-
War-driving and attacking lights in- cilitate the build up of consortia to
stalled in the Weizmann, or flying a successfully apply to several of these
drone over a high-security building opportunities.
in Beer Sheva (hosting the Israeli
CERT) and immediately compromis- If you are interested in partici-
ing all installed lights. pating in this session, and particu-
larly if you want to briefly present a
This is extremely fun to watch, project idea to get feedback and po-
true, but also extremely concerning, tentially start building-up a consor-
particularly taking into account the During the recent ESC 2017, tium, please contact me for booking
very real possibility of creating a there was much talk about EU fund- a slot.
worm that will automatically spread ing. There seems to be a number
unnoticed and could possibly infect of good consortia building up to In addition, we will discuss Marie
all buildings in a large city if only target (good news, Switzerland is Curie mobility grants as well.
the density of smart lights is over a back in!) the April call on Cryp-
threshold. tography https://goo.gl/6SRvF3 Open Positions

Cryptacus Newsletter
m Cryptacus.eu B cryptacus.newsletter@irisa.fr Page 2
permanent position. Deadline is most attractive position in this
23rd February 2017. More info February list, as Durham is a
at https://goo.gl/aiqfxq. small and beautiful city and the
university is one of the best
• Associate/Assistant Professor in in the UK. The initial salary
Formal Methods Technical Uni- will be circa £85,000 and may
Please send us any employment op-
versity of Denmark - DTU Com- rise significantly higher, typi-
portunity you want to publicize in
pute. Deadline is 5th February cally around £120,000 depend-
the newsletter.
2017. Full time, permanent po- ing on experience and achieved
sition. For further info or to targets.
There are still 2 open posi-
apply, check https://goo.gl/
tions at Kent in the security do-
3CHl2z.
main, at assistant professor level, full For other interesting positions
time and permanent. Salary range • Lecturer or Senior Lecturer or all across Europe, please check the
is £32,958 to £46,924. Deadline is Reader in Systems for the In- recently revamped ’Researchers in
6th February, so hurry up! Please ternet of Things at the Uni- Motion’ portal https://euraxess.
come to join an expanding team with versity of Edinburgh - School ec.europa.eu/.
many funding successes in Cyberse- of Informatics. Closes on the
curity! More info at https://goo. 15th February 2017. Another Proposals for STSMs
gl/tHulul. Also, there is now an full time, permanent position.
open position for a fully funded 3- Salary range is £39,324 to
years long PhD studentship with me, £55,998. Edinburgh is one of
so if you want to apply, please check the nicest places to leave in
https://goo.gl/YxDzTt. the UK, its university is ex-
Other interesting positions are: tremely prestigious and the cost
of living and accommodation
• Chair in Cyber-Secure Engi- is reasonably low. Also, they’re
neering Systems and Processes very welcoming of foreigners, By now, you should be already
at Cranfield University - School much more than their neigh- familiar with what Short Term Scien-
of Aerospace, Transport and bors to the South, and there’s tific Missions (or STSMs, for short)
Manufacturing (SATM). This the off-chance possibility that are, but we have a healthy budget for
professorship is full-time, per- they might not Brexit as they them within the Cryptacus project
manent. One of the topics voted against and they current and not enough demand.
they’re interested in is ’Secu- leaders are strongly opposed to
rity of Internet of Things (IoT) it. Or maybe they will do, later We will repeat the STSM offer of
devices and systems within in- claim independence and try to Aurélien Francillon from last month:
dustrial settings’. The closing re-enter the EU. For more info,
date is 9th February 2017. Ini- visit https://goo.gl/KNB9QD. “At Eurecom we are actively work-
tial salary is £66,366. More info ing on analyzing embedded devices
at https://goo.gl/aZczjS • Lecturer- Internet of Things, at software and building methodologies
University of Essex - School and tools for this. An example of that
• Lecturer/SL/Reader in Cyber of Computer Science and Elec- is our open source Avatar Framework
Security at the School of Com- tronic Engineering. Full time, (see http://s3.eurecom.fr/tools/
puting Science, University of permanent position, with a avatar/) which is aimed to reverse
Glasgow. Another full time, per- deadline on the 7th February engineer devices and search for vul-
manent position with a salary 2017. The position is based nerabilities. We are happy to receive
range between £33,943 and in Colchester, one of the most visitors interested in the topic, for
£55,998 per annum. Deadline beautiful and greenest cam- example to get help to start using the
is the 3rd of February. More info puses in the UK, and its salary Avatar framework on a given device.”
at https://goo.gl/ioChFq. range is £39,324 to £46,924.
More details at https://goo.
• Lecturer or Senior Lecturer gl/cSXjXP.
in Internet of Things (IoT)
and Cyber security at Liverpool • Professor in Department of
John Moores University - Com- Computer Science (with sub-
puter Science and Electron- sequent Department Headship)
ics and Electrical Engineering. at Durham University - Depart-
Starting salary is in the range ment of Computer Science. This
£39,324 to £48,327. Full time, is in my opinion one of the

Cryptacus Newsletter
m Cryptacus.eu B cryptacus.newsletter@irisa.fr Page 3
I will be happy to receive anyone guess. And as long as the ransom The summer school on real-world
interested in investigating the many price isn’t too onerous, people will crypto and privacy organised by Lejla
limitations and pitfalls of the PRNGs pay.’ You can read more, and many in- will take place in Sibenik (Croatia),
and the TRNGs currently in use on teresting comments from readers, at June 5 to 9. Highly recommended,
IoT devices. https://goo.gl/sc92MA. for all ages! Registration will open
Another interesting reading can early February 2017. More relevant
Blogs and posts to read be found in the article ’How the info at https://goo.gl/cSCcUZ.
Internet of Things will affect secu-
rity & privacy’ by Andrew Meola for Esorics is this year in beautiful
Business Insider at https://goo.gl/ Oslo, from 11-15 September. Submis-
He3tCE. sion deadline is April 19th . Hope to
see many of you there!

Last but not least, Agusti Solanas


On his blog ’Schneier on Security’, is editing an Special Issue in the
Bruce covers the IoT Ransomware at- International Journal of RF Tech-
tack against a Luxury Austrian Hotel, nologies Research and Applications
with links to a New York times ar- Event calendar (ISSN: 1754-5730) on ‘Advances in
ticle and one on the local Austrian Of course, the main dish in our RFID for Smart Cities’ with a dead-
press. He disputes some of the most event calendar is the next Crypta- line of 17th March and a publica-
alarming elements of the story, but cus Management Committee & Work- tion date in September. More info at
offers a very worrying and probably shop in March, 14-15th, in Sutomore, https://goo.gl/YbjggH
prophetic personal opinion: ’I expect Montenegro. It will be organised by
IoT ransomware to become a major Milena Djukanovic. See you all very soon!
area of crime in the next few years. Euro S&P is this year in Paris,
How long before we see this tac- 26-28 April. A must! More at https: Best,
tic used against cars? Against home //goo.gl/fvjBVN Julio Hernandez-Castro
thermostats? Within the year is my

Cryptacus Newsletter
m Cryptacus.eu B cryptacus.newsletter@irisa.fr Page 4

Das könnte Ihnen auch gefallen