<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>| Lost in the Noise |</title>
	<atom:link href="https://van-manen.info/weblog/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>https://van-manen.info/weblog</link>
	<description></description>
	<lastBuildDate>Wed, 06 Jul 2022 09:12:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.0</generator>

<image>
	<url>https://van-manen.info/weblog/wp-content/uploads/2016/02/cropped-analog-32x32.jpg</url>
	<title>| Lost in the Noise |</title>
	<link>https://van-manen.info/weblog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Europarlementariërs willen onderzoek naar schaduwlobby van Big Tech</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/06/europarlementariers-willen-onderzoek-naar-schaduwlobby-van-big-tech/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/06/europarlementariers-willen-onderzoek-naar-schaduwlobby-van-big-tech/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 06 Jul 2022 09:12:44 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/06/europarlementariers-willen-onderzoek-naar-schaduwlobby-van-big-tech/</guid>

					<description><![CDATA[Drie Europarlementariërs, waaronder de Nederlander Paul Tang, willen dat er een onderzoek komt naar de schaduwlobby van Big &#8230;Drie Europarlementariërs, waaronder de Nederlander Paul Tang,...]]></description>
										<content:encoded><![CDATA[<p>Drie Europarlementariërs, waaronder de Nederlander Paul Tang, willen dat er een onderzoek komt naar de schaduwlobby van Big &#8230;Drie Europarlementariërs, waaronder de Nederlander Paul Tang, willen dat er een onderzoek komt naar de schaduwlobby van Big &#8230;<a href="https://www.security.nl/posting/759782/Europarlementari%C3%ABrs+willen+onderzoek+naar+schaduwlobby+van+Big+Tech?channel=rss" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/06/europarlementariers-willen-onderzoek-naar-schaduwlobby-van-big-tech/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Ministerie van Volksgezondheid maakt scantool KAT open source</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/06/ministerie-van-volksgezondheid-maakt-scantool-kat-open-source/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/06/ministerie-van-volksgezondheid-maakt-scantool-kat-open-source/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 06 Jul 2022 08:35:00 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/06/ministerie-van-volksgezondheid-maakt-scantool-kat-open-source/</guid>

					<description><![CDATA[Het ministerie van Volksgezondheid heeft de zelfontwikkelde scantool KAT open source gemaakt, zo laat minister Kuipers in een &#8230;Het ministerie van Volksgezondheid heeft de zelfontwikkelde...]]></description>
										<content:encoded><![CDATA[<p>Het ministerie van Volksgezondheid heeft de zelfontwikkelde scantool KAT open source gemaakt, zo laat minister Kuipers in een &#8230;Het ministerie van Volksgezondheid heeft de zelfontwikkelde scantool KAT open source gemaakt, zo laat minister Kuipers in een &#8230;<a href="https://www.security.nl/posting/759776/Ministerie+van+Volksgezondheid+maakt+scantool+KAT+open+source?channel=rss" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/06/ministerie-van-volksgezondheid-maakt-scantool-kat-open-source/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Wanneer is er sprake van een algoritme of een AI-systeem?</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/06/wanneer-is-er-sprake-van-een-algoritme-of-een-ai-systeem/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/06/wanneer-is-er-sprake-van-een-algoritme-of-een-ai-systeem/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 06 Jul 2022 08:13:40 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/06/wanneer-is-er-sprake-van-een-algoritme-of-een-ai-systeem/</guid>

					<description><![CDATA[Juridische vraag: Vier Utrechtse gemeenten, Nieuwegein, IJsselstein, Houten en Lopik, hebben bij de bestrijding van &#8230;Juridische vraag: Vier Utrechtse gemeenten, Nieuwegein, IJsselstein, Houten en Lopik,...]]></description>
										<content:encoded><![CDATA[<p>Juridische vraag: Vier Utrechtse gemeenten, Nieuwegein, IJsselstein, Houten en Lopik, hebben bij de bestrijding van &#8230;Juridische vraag: Vier Utrechtse gemeenten, Nieuwegein, IJsselstein, Houten en Lopik, hebben bij de bestrijding van &#8230;<a href="https://www.security.nl/posting/759763/Wanneer+is+er+sprake+van+een+algoritme+of+een+AI-systeem%3F?channel=rss" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/06/wanneer-is-er-sprake-van-een-algoritme-of-een-ai-systeem/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>EFF: nieuwe EU-wet geeft overheden teveel macht om content te verwijderen</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/06/eff-nieuwe-eu-wet-geeft-overheden-teveel-macht-om-content-te-verwijderen/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/06/eff-nieuwe-eu-wet-geeft-overheden-teveel-macht-om-content-te-verwijderen/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 06 Jul 2022 07:49:30 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/06/eff-nieuwe-eu-wet-geeft-overheden-teveel-macht-om-content-te-verwijderen/</guid>

					<description><![CDATA[De Digital Services Act (DSA) waar het Europees Parlement gisteren mee akkoord ging geeft overheidsinstanties teveel macht om &#8230;De Digital Services Act (DSA) waar het...]]></description>
										<content:encoded><![CDATA[<p>De Digital Services Act (DSA) waar het Europees Parlement gisteren mee akkoord ging geeft overheidsinstanties teveel macht om &#8230;De Digital Services Act (DSA) waar het Europees Parlement gisteren mee akkoord ging geeft overheidsinstanties teveel macht om &#8230;<a href="https://www.security.nl/posting/759762/EFF%3A+nieuwe+EU-wet+geeft+overheden+teveel+macht+om+content+te+verwijderen?channel=rss" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/06/eff-nieuwe-eu-wet-geeft-overheden-teveel-macht-om-content-te-verwijderen/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hive Ransomware Upgrades to Rust for More Sophisticated Encryption Method</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/06/hive-ransomware-upgrades-to-rust-for-more-sophisticated-encryption-method/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/06/hive-ransomware-upgrades-to-rust-for-more-sophisticated-encryption-method/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 06 Jul 2022 07:09:04 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/06/hive-ransomware-upgrades-to-rust-for-more-sophisticated-encryption-method/</guid>

					<description><![CDATA[<img width="150" height="136" src="https://van-manen.info/weblog/wp-content/uploads/2022/07/malware-5A1Wdv-150x136.jpeg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="" />The operators of the Hive ransomware-as-a-service (RaaS) scheme have overhauled their file-encrypting software to fully migrate to Rust and adopt a more sophisticated encryption method....]]></description>
										<content:encoded><![CDATA[<img width="150" height="136" src="https://van-manen.info/weblog/wp-content/uploads/2022/07/malware-5A1Wdv-150x136.jpeg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="" loading="lazy" /><p>The operators of the Hive ransomware-as-a-service (RaaS) scheme have overhauled their file-encrypting software to fully migrate to Rust and adopt a more sophisticated encryption method.<br />
&#8220;With its latest variant carrying several major upgrades, Hive also proves it&#8217;s one of the fastest evolving ransomware families, exemplifying the continuously changing ransomware ecosystem,&#8221; Microsoft ThreatThe operators of the Hive ransomware-as-a-service (RaaS) scheme have overhauled their file-encrypting software to fully migrate to Rust and adopt a more sophisticated encryption method.<br />
&#8220;With its latest variant carrying several major upgrades, Hive also proves it&#8217;s one of the fastest evolving ransomware families, exemplifying the continuously changing ransomware ecosystem,&#8221; Microsoft Threat<a href="https://thehackernews.com/2022/07/hive-ransomware-upgrades-to-rust-for.html" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/06/hive-ransomware-upgrades-to-rust-for-more-sophisticated-encryption-method/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIST Picks Four Quantum-Resistant Cryptographic Algorithms</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/05/nist-picks-four-quantum-resistant-cryptographic-algorithms/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/05/nist-picks-four-quantum-resistant-cryptographic-algorithms/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 05 Jul 2022 23:56:37 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/05/nist-picks-four-quantum-resistant-cryptographic-algorithms/</guid>

					<description><![CDATA[The US Department of Commerce&#8217;s National Institute of Standards and Technology (NIST) announced the first group of encryption tools that will become part of its...]]></description>
										<content:encoded><![CDATA[<p>The US Department of Commerce&#8217;s National Institute of Standards and Technology (NIST) announced the first group of encryption tools that will become part of its post-quantum cryptographic standard.The US Department of Commerce&#8217;s National Institute of Standards and Technology (NIST) announced the first group of encryption tools that will become part of its post-quantum cryptographic standard.<a href="https://www.darkreading.com/emerging-tech/nist-picks-four-quantum-resistant-cryptographic-algorithms" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/05/nist-picks-four-quantum-resistant-cryptographic-algorithms/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2022 H1 IRAP report is now available on AWS Artifact</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/05/2022-h1-irap-report-is-now-available-on-aws-artifact/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/05/2022-h1-irap-report-is-now-available-on-aws-artifact/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 05 Jul 2022 22:09:23 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/05/2022-h1-irap-report-is-now-available-on-aws-artifact/</guid>

					<description><![CDATA[We’re excited to announce that a new Information Security Registered Assessors Program (IRAP) report is now available on AWS Artifact. Amazon Web Services (AWS) successfully...]]></description>
										<content:encoded><![CDATA[<p>We’re excited to announce that a new Information Security Registered Assessors Program (IRAP) report is now available on <a href="https://aws.amazon.com/artifact/" target="_blank" rel="noopener">AWS Artifact</a>. <a href="https://aws.amazon.com/" target="_blank" rel="noopener">Amazon Web Services (AWS)</a> successfully completed an IRAP assessment in May 2022 by an independent <a href="https://www.cyber.gov.au/acsc/view-all-content/programs/irap/irap-assessors" target="_blank" rel="noopener">ASD (Australian Signals Directorate) certified IRAP assessor</a>. The new IRAP report includes an additional nine AWS services that are now assessed at the PROTECTED classification under IRAP. This brings the total number of services assessed at PROTECTED to 132.</p>
<p>For a full list of these services, see the IRAP tab on the <a href="https://aws.amazon.com/compliance/services-in-scope/" target="_blank" rel="noopener">AWS Services in Scope</a> page. The following services are the nine newly assessed services:</p>
<p><a href="https://aws.amazon.com/audit-manager/" target="_blank" rel="noopener">AWS Audit Manager</a><br />
 <a href="https://aws.amazon.com/chatbot/" target="_blank" rel="noopener">AWS Chatbot</a><br />
 <a href="https://aws.amazon.com/data-exchange/" target="_blank" rel="noopener">AWS Data Exchange</a><br />
 <a href="https://aws.amazon.com/forecast/" target="_blank" rel="noopener">Amazon Forecast</a><br />
 <a href="https://aws.amazon.com/glue/features/databrew/" target="_blank" rel="noopener">AWS Glue DataBrew</a><br />
 <a href="https://aws.amazon.com/iot-sitewise/" target="_blank" rel="noopener">AWS IoT SiteWise</a><br />
 <a href="https://aws.amazon.com/managed-services/" target="_blank" rel="noopener">AWS Managed Services</a><br />
 <a href="https://aws.amazon.com/personalize/" target="_blank" rel="noopener">Amazon Personalize</a><br />
 <a href="https://aws.amazon.com/snowball/" target="_blank" rel="noopener">AWS Snowball Edge</a> </p>
<p>The IRAP documentation pack is developed in accordance with the Australian Cyber Security Centre (ACSC) <a href="https://www.cyber.gov.au/acsc/government/cloud-security-guidance" target="_blank" rel="noopener">Cloud Security Guidance</a> and their <a href="https://www.cyber.gov.au/acsc/view-all-content/publications/anatomy-cloud-assessment-and-authorisation" target="_blank" rel="noopener">Anatomy of a Cloud Assessment and Authorisation</a> framework, which addresses guidance within the <a href="https://www.cyber.gov.au/acsc/view-all-content/ism" target="_blank" rel="noopener">Australian Government Information Security Manual (ISM)</a>, the Attorney-General’s <a href="https://www.protectivesecurity.gov.au/" target="_blank" rel="noopener">Protective Security Policy Framework (PSPF)</a>, and the Digital Transformation Agency (DTA) <a href="https://www.dta.gov.au/our-projects/secure-cloud-strategy" target="_blank" rel="noopener">Secure Cloud Strategy</a>.</p>
<p>The IRAP package on <a href="https://aws.amazon.com/artifact/" target="_blank" rel="noopener">AWS Artifact</a> also includes the <em>AWS Consumer Guide</em> and the whitepaper <em>Reference Architectures for ISM PROTECTED Workloads in the AWS Cloud.</em></p>
<p>The IRAP documentation pack is developed to assist Australian government agencies and their partners to plan, architect, and assess risk for their workloads when they use AWS Cloud services. Reach out to your AWS representatives to let us know which additional services you would like to see in scope for upcoming IRAP assessments. We strive to bring more services into scope at the PROTECTED level to support your requirements.</p>
<p>If you have feedback about this post, submit comments in the <strong>Comments</strong> section below.</p>
<p><strong>Want more AWS Security how-to content, news, and feature announcements? Follow us on <a href="https://twitter.com/AWSsecurityinfo" title="Twitter" target="_blank" rel="noopener">Twitter</a>.</strong></p>
<div class="blog-author-box">
<div class="blog-author-image">
   </div>
<h3 class="lb-h4">Matt Brunker</h3>
<p>Matt is the security program manager for the Australia and New Zealand region, leading multiple security certification programs. Matt is a passionate cybersecurity professional with a strong background in assisting organisations in the design, implementation, and monitoring of security controls.</p>
</div>
<p>We’re excited to announce that a new Information Security Registered Assessors Program (IRAP) report is now available on AWS Artifact. Amazon Web Services (AWS) successfully completed an IRAP assessment in May 2022 by an independent ASD (Australian Signals Directorate) certified IRAP assessor. The new IRAP report includes an additional nine AWS services that are now<a href="https://aws.amazon.com/blogs/security/2022-h1-irap-report-is-now-available-on-aws-artifact/" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/05/2022-h1-irap-report-is-now-available-on-aws-artifact/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>HackerOne Employee Fired for Stealing and Selling Bug Reports for Personal Gain</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/05/hackerone-employee-fired-for-stealing-and-selling-bug-reports-for-personal-gain/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/05/hackerone-employee-fired-for-stealing-and-selling-bug-reports-for-personal-gain/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 05 Jul 2022 21:29:56 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/05/hackerone-employee-fired-for-stealing-and-selling-bug-reports-for-personal-gain/</guid>

					<description><![CDATA[Company says it is making changes to its security controls to prevent malicious insiders from doing the same thing in future; reassures bug hunters their...]]></description>
										<content:encoded><![CDATA[<p>Company says it is making changes to its security controls to prevent malicious insiders from doing the same thing in future; reassures bug hunters their bounties are safe.Company says it is making changes to its security controls to prevent malicious insiders from doing the same thing in future; reassures bug hunters their bounties are safe.<a href="https://www.darkreading.com/vulnerabilities-threats/hackerone-employee-fired-for-stealing-and-selling-bug-reports-for-personal-gain" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/05/hackerone-employee-fired-for-stealing-and-selling-bug-reports-for-personal-gain/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Supply Chain Attack Deploys Hundreds of Malicious NPM Modules to Steal Data</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/05/supply-chain-attack-deploys-hundreds-of-malicious-npm-modules-to-steal-data/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/05/supply-chain-attack-deploys-hundreds-of-malicious-npm-modules-to-steal-data/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 05 Jul 2022 20:40:36 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/05/supply-chain-attack-deploys-hundreds-of-malicious-npm-modules-to-steal-data/</guid>

					<description><![CDATA[A widespread campaign uses more than 24 malicious NPM packages loaded with JavaScript obfuscators to steal form data from multiple sites and apps, analysts report.A...]]></description>
										<content:encoded><![CDATA[<p>A widespread campaign uses more than 24 malicious NPM packages loaded with JavaScript obfuscators to steal form data from multiple sites and apps, analysts report.A widespread campaign uses more than 24 malicious NPM packages loaded with JavaScript obfuscators to steal form data from multiple sites and apps, analysts report.<a href="https://www.darkreading.com/attacks-breaches/supply-chain-attack-malicious-npm-modules-steal-data" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/05/supply-chain-attack-deploys-hundreds-of-malicious-npm-modules-to-steal-data/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to tune TLS for hybrid post-quantum cryptography with Kyber</title>
		<link>https://van-manen.info/weblog/index.php/2022/07/05/how-to-tune-tls-for-hybrid-post-quantum-cryptography-with-kyber/</link>
					<comments>https://van-manen.info/weblog/index.php/2022/07/05/how-to-tune-tls-for-hybrid-post-quantum-cryptography-with-kyber/#respond</comments>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 05 Jul 2022 17:07:22 +0000</pubDate>
				<category><![CDATA[InfoSec]]></category>
		<guid isPermaLink="false">https://van-manen.info/weblog/index.php/2022/07/05/how-to-tune-tls-for-hybrid-post-quantum-cryptography-with-kyber/</guid>

					<description><![CDATA[We are excited to offer hybrid post-quantum TLS with Kyber for AWS Key Management Service (AWS KMS) and AWS Certificate Manager (ACM). In this blog...]]></description>
										<content:encoded><![CDATA[<p>We are excited to offer <a href="https://aws.amazon.com/about-aws/whats-new/2022/03/aws-kms-acm-support-latest-hybrid-post-quantum-tls-ciphers/" target="_blank" rel="noopener">hybrid post-quantum TLS with Kyber</a> for <a href="http://aws.amazon.com/kms" target="_blank" rel="noopener">AWS Key Management Service (AWS KMS)</a> and <a href="http://aws.amazon.com/acm" target="_blank" rel="noopener">AWS Certificate Manager (ACM)</a>. In this blog post, we share the performance characteristics of our hybrid post-quantum Kyber implementation, show you how to configure a Maven project to use it, and discuss how to prepare your connection settings for Kyber post-quantum cryptography (PQC).</p>
<p>After five years of intensive research and cryptanalysis among partners from academia, the cryptographic community, and the <a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="noopener">National Institute of Standards and Technology (NIST)</a>, NIST has selected <a href="https://pq-crystals.org/kyber/index.shtml" target="_blank" rel="noopener">Kyber</a> for post-quantum key encapsulation mechanism (KEM) standardization. This marks the beginning of the next generation of public key encryption. In time, the classical key establishment algorithms we use today, like RSA and elliptic curve cryptography (ECC), will be replaced by quantum-secure alternatives. At AWS Cryptography, we’ve been researching and analyzing the candidate KEMs through each round of the NIST selection process. We began supporting Kyber in <a href="https://aws.amazon.com/blogs/security/round-2-post-quantum-tls-is-now-supported-in-aws-kms/" target="_blank" rel="noopener">round 2</a> and continue that support today.</p>
<p>A cryptographically relevant quantum computer that is capable of breaking RSA and ECC does not yet exist. However, we are offering hybrid post-quantum TLS with Kyber today so that customers can see how the performance differences of PQC affect their workloads. We also believe that the use of PQC raises the already-high security bar for connecting to <a href="http://aws.amazon.com/kms" target="_blank" rel="noopener">AWS KMS</a> and <a href="http://aws.amazon.com/acm" target="_blank" rel="noopener">ACM</a>, making this feature attractive for customers with long-term confidentiality needs.</p>
<h2>Performance of hybrid post-quantum TLS with Kyber</h2>
<p>Hybrid post-quantum TLS incurs a latency and bandwidth overhead compared to classical crypto alone. To quantify this overhead, we measured how long <a href="https://github.com/aws/s2n-tls" target="_blank" rel="noopener">S2N-TLS</a> takes to negotiate hybrid post-quantum (ECDHE + Kyber) key establishment compared to ECDHE alone. We performed the tests with the <a href="https://perf.wiki.kernel.org/" target="_blank" rel="noopener">Linux perf</a> subsystem on an <a href="http://aws.amazon.com/ec2" target="_blank" rel="noopener">Amazon Elastic Compute Cloud (Amazon EC2</a>) c6i.4xlarge instance in the US East (Northern Virginia) AWS Region, and we initiated 2,000 TLS connections to a test server running in the US West (Oregon) Region, to include typical internet latencies.</p>
<p>Figure 1 shows the latencies of a TLS handshake that uses classical <a href="https://en.wikipedia.org/wiki/Elliptic-curve_Diffie%E2%80%93Hellman" target="_blank" rel="noopener">ECDHE</a> and hybrid post-quantum (ECDHE + Kyber) key establishment. The columns are separated to illustrate the CPU time spent by the client and server compared to the time spent sending data over the network.</p>
<div class="wp-caption aligncenter">
<p class="wp-caption-text">Figure 1: Latency of classical compared to hybrid post-quantum TLS handshake</p>
</div>
<p>Figure 2 shows the bytes sent and received during the TLS handshake, as measured by the client, for both classical ECDHE and hybrid post-quantum (ECDHE + Kyber) key establishment.</p>
<div class="wp-caption aligncenter">
<p class="wp-caption-text">Figure 2: Bandwidth of classical compared to hybrid post-quantum TLS handshake</p>
</div>
<p>This data shows that the overhead for using hybrid post-quantum key establishment is 0.25 ms on the client, 0.23 ms on the server, and an additional 2,356 bytes on the wire. Intra-Region tests would result in lower network latency. Your latencies also might vary depending on network conditions, CPU performance, server load, and other variables.</p>
<p>The results show that the performance of Kyber is strong; the additional latency is one of the top contenders among the NIST PQC candidates that we analyzed in a <a href="https://aws.amazon.com/blogs/security/round-2-post-quantum-tls-is-now-supported-in-aws-kms/" target="_blank" rel="noopener">previous blog post</a>. In fact, the performance of these ciphers has improved during our latest test, because x86-64 assembly-optimized versions of these ciphers are now available for use.</p>
<h2>Configure a Maven project for hybrid post-quantum TLS</h2>
<p>In this section, we provide a Maven configuration and code example that will show you how to get started using our assembly-optimized, hybrid post-quantum TLS configuration with Kyber.</p>
<p><strong>To configure a Maven project for hybrid post-quantum TLS</strong></p>
<p>Get the preview release of the <a href="https://aws.amazon.com/blogs/developer/introducing-aws-common-runtime-http-client-in-the-aws-sdk-for-java-2-x/" target="_blank" rel="noopener">AWS Common Runtime HTTP client for the AWS SDK for Java 2.x</a>. Your Maven dependency configuration should specify version 2.17.69-PREVIEW or newer, as shown in the following code sample. </p>
<div class="hide-language">
   &lt;dependency&gt;<br />
    &lt;groupId&gt;software.amazon.awssdk&lt;/groupId&gt;<br />
    aws-crt-client<br />
    &lt;version&gt;[2.17.69-PREVIEW,]&lt;/version&gt;<br />
&lt;/dependency&gt;
  </div>
<p> Configure the desired cipher suite in your code’s initialization. The following code sample configures an AWS KMS client to use the latest hybrid post-quantum cipher suite. </p>
<div class="hide-language">
   // Check platform support<br />
if(!TLS_CIPHER_PREF_PQ_TLSv1_0_2021_05.isSupported()){<br />
    throw new RuntimeException(“Hybrid post-quantum cipher suites are not supported.”);<br />
}
<p>// Configure HTTP client<br />
SdkAsyncHttpClient awsCrtHttpClient = AwsCrtAsyncHttpClient.builder()<br />
          .tlsCipherPreference(TLS_CIPHER_PREF_PQ_TLSv1_0_2021_05)<br />
          .build();</p>
<p>// Create the AWS KMS async client<br />
KmsAsyncClient kmsAsync = KmsAsyncClient.builder()<br />
         .httpClient(awsCrtHttpClient)<br />
         .build();
  </p></div>
<p>With that, all calls made with your AWS KMS client will use hybrid post-quantum TLS. You can use the latest hybrid post-quantum cipher suite with ACM by following the preceding example but using an <span>AcmAsyncClient</span> instead.</p>
<h2>Tune connection settings for hybrid post-quantum TLS</h2>
<p>Although hybrid post-quantum TLS has some latency and bandwidth overhead on the initial handshake, that cost is amortized over the duration of the TLS session, and you can fine-tune your connection settings to help further reduce the cost. In this section, you learn three ways to reduce the impact of hybrid PQC on your TLS connections: connection pooling, connection timeouts, and TLS session resumption.</p>
<h3>Connection pooling</h3>
<p>Connection pools manage the number of active connections to a server. They allow a connection to be reused without closing and reopening it, which amortizes the cost of connection establishment over time. Part of a connection’s setup time is the TLS handshake, so you can use connection pools to help reduce the impact of an increase in handshake latency.</p>
<p>To illustrate this, we wrote a test application that generates approximately 200 transactions per second to a test server. We varied the maximum concurrency setting of the HTTP client and measured the latency of the test request. In the AWS CRT HTTP client, this is the <span>maxConcurrency</span> setting. If the connection pool doesn’t have an idle connection available, the request latency includes establishing a new connection. Using Wireshark, we captured the network traffic to observe the number of TLS handshakes that took place over the duration of the application. Figure 3 shows the request latency and number of TLS handshakes as the <span>maxConcurrency</span> setting is increased.</p>
<div class="wp-caption aligncenter">
<p class="wp-caption-text">Figure 3: Median request latency and number of TLS handshakes as concurrency pool size increases</p>
</div>
<p>The biggest latency benefit occurred with a <span>maxConcurrency</span> value greater than 1. Beyond that, the latencies were past the point of diminishing returns. For all <span>maxConcurrency</span> values of 10 and below, additional TLS handshakes took place within the connections, but they didn’t have much impact on median latency. These inflection points will depend on your application’s request volume. The takeaway is that connection pooling allows connections to be reused, thereby spreading the cost of any increased TLS negotiation time over many requests.</p>
<p>More detail about using the maxConcurrency option can be found in the <a href="http://sdk.amazonaws.com/java/api/latest/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.Builder.html" target="_blank" rel="noopener">AWS SDK for Java API Reference</a>.</p>
<h3>Connection timeouts</h3>
<p>Connection timeouts work in conjunction with connection pooling. Even if you use a connection pool, there is a limit to how long idle connections stay open before the pool closes them. You can adjust this time limit to save on connection establishment overhead.</p>
<p>A nice way to visualize this setting is to imagine bursty traffic patterns. Despite tuning the connection pool concurrency, your connections keep closing because the burst period is longer than the idle time limit. By increasing the maximum idle time, you can reuse these connections despite bursty behavior.</p>
<p>To simulate the impact of connection timeouts, we wrote a test application that starts 10 threads, each of which activate at the same time on a periodic schedule every 5 seconds for a minute. We set <span>maxConcurrency</span> to 10 to allow each thread to have its own connection. We set <span>connectionMaxIdleTime</span> of the AWS CRT HTTP client to 1 second for the first test; and to 10 seconds for the second test.</p>
<p>When the maximum idle time was 1 second, the connections for all 10 threads closed during the time between each burst. As a result, 100 total connections were formed over the life of the test, causing a median request latency of 20.3 ms. When we changed the maximum idle time to 10 seconds, the 10 initial connections were reused by each subsequent burst, reducing the median request latency to 5.9 ms.</p>
<p>By setting the connectionMaxIdleTime appropriately for your application, you can reduce connection establishment overhead, including TLS negotiation time, to help achieve time savings throughout the life of your application.</p>
<p>More detail about using the <span>connectionMaxIdleTime</span> option can be found in the <a href="http://sdk.amazonaws.com/java/api/latest/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.Builder.html" target="_blank" rel="noopener">AWS SDK for Java API Reference</a>.</p>
<h3>TLS session resumption</h3>
<p>TLS session resumption allows a client and server to bypass the key agreement that is normally performed to arrive at a new shared secret. Instead, communication quickly resumes by using a shared secret that was previously negotiated, or one that was derived from a previous secret (the implementation details depend on the version of TLS in use). This feature requires that both the client and server support it, but if available, TLS session resumption allows the TLS handshake time and bandwidth increases associated with hybrid PQ to be amortized over the life of multiple connections.</p>
<h2>Conclusion</h2>
<p>As you learned in this post, hybrid post-quantum TLS with Kyber is available for AWS KMS and ACM. This new cipher suite raises the security bar and allows you to prepare your workloads for post-quantum cryptography. Hybrid key agreement has some additional overhead compared to classical ECDHE, but you can mitigate these increases by tuning your connection settings, including connection pooling, connection timeouts, and TLS session resumption. Begin using hybrid key agreement today with <a href="http://aws.amazon.com/kms" target="_blank" rel="noopener">AWS KMS</a> and <a href="http://aws.amazon.com/acm" target="_blank" rel="noopener">ACM</a>.</p>
<p> <br />If you have feedback about this post, submit comments in the<strong> Comments</strong> section below.</p>
<p><strong>Want more AWS Security news? Follow us on <a title="Twitter" href="https://twitter.com/AWSsecurityinfo" target="_blank" rel="noopener">Twitter</a>.</strong></p>
<div class="blog-author-box">
<div class="blog-author-image">
   </div>
<h3 class="lb-h4">Brian Jarvis</h3>
<p>Brian is a Senior Software Engineer at AWS Cryptography. His interests are in post-quantum cryptography and cryptographic hardware. Previously, Brian worked in AWS Security, developing internal services used throughout the company. Brian holds a Bachelor’s degree from Vanderbilt University and a Master’s degree from George Mason University in Computer Engineering. He plans to finish his PhD “some day”.</p>
</div>
<p>We are excited to offer hybrid post-quantum TLS with Kyber for AWS Key Management Service (AWS KMS) and AWS Certificate Manager (ACM). In this blog post, we share the performance characteristics of our hybrid post-quantum Kyber implementation, show you how to configure a Maven project to use it, and discuss how to prepare your connection<a href="https://aws.amazon.com/blogs/security/how-to-tune-tls-for-hybrid-post-quantum-cryptography-with-kyber/" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://van-manen.info/weblog/index.php/2022/07/05/how-to-tune-tls-for-hybrid-post-quantum-cryptography-with-kyber/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
