Skip to Content
Java Cryptography
book

Java Cryptography

by Jonathan Knudsen
May 1998
Intermediate to advanced
362 pages
10h 8m
English
O'Reilly Media, Inc.
Content preview from Java Cryptography

Endpoint Security

Most of cryptography is concerned with securing communications between two parties. This requires two elements: cryptography for authentication and session encryption, and trusted executable code at each endpoint. It’s the “trusted executable code” that concerns us here.

Think back to the SafeTalk application in Chapter 10. How could it be compromised by messing around with class files?

  • You could modify the javax.crypto.CipherOutputStream class to send plaintext to another IP address, unbeknownst to the user.

  • You could modify the Session class to always choose the same key for encryption. Intercepted communications could then be easily decrypted.

And how would these class files be modified? A virus could do the work, or a rogue ActiveX control. If the class files come from a file server, they might be modified in transit from the server to your computer.

An interesting paper describes how a Netscape exectuable was modified in transit from server to client, available at http://http.cs.berkeley.edu/~gauthier/endpoint-security.html. The technique of NFS spoofing described in the paper could easily be used to modify class files instead of binary executables.

How can you prevent this kind of attack? Inside your application, there’s nothing you can do because it’s the class files of your application that get modified in this attack. Outside your application, you can take the following measures:

  • Don’t use an insecure file transfer protocol to obtain executables. In the paper ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Hands-On Cryptography with Java

Hands-On Cryptography with Java

Erik Costlow
Java Security Handbook

Java Security Handbook

Jamie Jaworski, Paul J. Perrone, Venkata S.R. Krishna Chaganti

Publisher Resources

ISBN: 1565924029Errata Page