Wednesday December 3, 2008 6:41 AM AEST
Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Google tries its hand at cryptography

  • Email a Friend
  • Print Page
Google tries its hand at cryptography
By Shaun Nichols
Aug 13, 2008 9:34 AM
Tags: Google | cryptography | encryption | security
The aim of the tool is to provide developers with a more secure and reliable cryptography tool that can easily be inserted into their code, according to Steve Weis, the Google security software engineer who helped develop KetCzar.

"Cryptography is notoriously hard to get right and if improperly used, can create serious security holes," Weiss wrote in a company blog posting.

Weiss explained that common mistakes, such as using outdated algorithms or not being able to rotate in new encryption keys can render the tools completely useless.

The aim of Key Czar was to simplify those acts and allow developers to not only put cryptography tools in place, but also manage and change encryption keys if need be.

"Keyczar's key versioning system makes it easy to rotate and revoke keys, without worrying about backward compatibility or making any changes to source code," he wrote.

Google warns, however, that KeyCzar should not be viewed as a complete cryptography system. It does not contain any actual crypto libraries and does not perform many of the actual cryptography tasks.

"Keyczar is essentially a library, and doesn't actually serve keys or certificates," the project's developers said on a 'non-goals' page.

"Keyczar keys are just flat files in a directory."

The first versions of KeyCzar are being made available for download on the Google Code service. The tool is currently limited to the Java and Python programming languages, but Google plans to release a C++ version shortly.

The company is also inviting third parties to get involved with the project. Developers can join through KeyCzar's Google Code page.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers