{"product_id":"cryptography-for-dummies-isbn-9780764541889","title":"Cryptography For Dummies","description":"\u003cul\u003e \u003cli\u003eCryptography is the most effective way to achieve data security and is essential to e-commerce activities such as online shopping, stock trading, and banking\u003c\/li\u003e \u003cli\u003eThis invaluable introduction to the basics of encryption covers everything from the terminology used in the field to specific technologies to the pros and cons of different implementations\u003c\/li\u003e \u003cli\u003eDiscusses specific technologies that incorporate cryptography in their design, such as authentication methods, wireless encryption, e-commerce, and smart cards\u003c\/li\u003e \u003cli\u003eBased entirely on real-world issues and situations, the material provides instructions for already available technologies that readers can put to work immediately\u003c\/li\u003e \u003cli\u003eExpert author Chey Cobb is retired from the NRO, where she held a Top Secret security clearance, instructed employees of the CIA and NSA on computer security and helped develop the computer security policies used by all U.S. intelligence agencies\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003eIntroduction  1\u003c\/p\u003e \u003cp\u003eAbout This Book 2\u003c\/p\u003e \u003cp\u003eHow to Use This Book 2\u003c\/p\u003e \u003cp\u003eWhat You Don’t Need to Read  3\u003c\/p\u003e \u003cp\u003eFoolish Assumptions 3\u003c\/p\u003e \u003cp\u003eHow This Book Is Organized 3\u003c\/p\u003e \u003cp\u003ePart I: Crypto Basics \u0026amp; What You Really Need to Know 4\u003c\/p\u003e \u003cp\u003ePart II: Public Key Infrastructure  4\u003c\/p\u003e \u003cp\u003ePart III: Putting Encryption Technologies to Work for You 4\u003c\/p\u003e \u003cp\u003ePart IV: The Part of Tens  4\u003c\/p\u003e \u003cp\u003ePart V: Appendixes 5\u003c\/p\u003e \u003cp\u003eIcons Used in This Book  5\u003c\/p\u003e \u003cp\u003eWhere to Go from Here  5\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart I: Crypto Basics \u0026amp; What You Really Need to Know 7\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1: A Primer on Crypto Basics  9\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIt’s Not about James Bond  9\u003c\/p\u003e \u003cp\u003eGo with the rhythm  10\u003c\/p\u003e \u003cp\u003eRockin’ the rhythm 11\u003c\/p\u003e \u003cp\u003eGetting to Know the Basic Terms 12\u003c\/p\u003e \u003cp\u003eWhat Makes a Cipher? 13\u003c\/p\u003e \u003cp\u003eConcealment ciphers 13\u003c\/p\u003e \u003cp\u003eSubstitution ciphers 14\u003c\/p\u003e \u003cp\u003eTransposition ciphers  15\u003c\/p\u003e \u003cp\u003eHash without the corned beef  16\u003c\/p\u003e \u003cp\u003eXOR what? 17\u003c\/p\u003e \u003cp\u003eBreaking Ciphers  20\u003c\/p\u003e \u003cp\u003eNot-so-secret keys  20\u003c\/p\u003e \u003cp\u003eKnown plaintext  21\u003c\/p\u003e \u003cp\u003ePattern recognition  21\u003c\/p\u003e \u003cp\u003eWhat a brute! 21\u003c\/p\u003e \u003cp\u003eCryptosystems 22\u003c\/p\u003e \u003cp\u003eEveryday Uses of Encryption 23\u003c\/p\u003e \u003cp\u003eNetwork logons and passwords 23\u003c\/p\u003e \u003cp\u003eSecure Web transactions 25\u003c\/p\u003e \u003cp\u003eATMs  26\u003c\/p\u003e \u003cp\u003eMusic and DVDs  27\u003c\/p\u003e \u003cp\u003eCommunication devices  28\u003c\/p\u003e \u003cp\u003eWhy Encryption Isn’t More Commonplace 28\u003c\/p\u003e \u003cp\u003eDifficulty in understanding the technology  29\u003c\/p\u003e \u003cp\u003eYou can’t do it alone  29\u003c\/p\u003e \u003cp\u003eSharing those ugly secrets  30\u003c\/p\u003e \u003cp\u003eCost may be a factor  30\u003c\/p\u003e \u003cp\u003eSpecial administration requirements 31\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2: Major League Algorithms  33\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBeware of “Snake Oil”  34\u003c\/p\u003e \u003cp\u003eSymmetric Keys Are All the Same  37\u003c\/p\u003e \u003cp\u003eThe key table 37\u003c\/p\u003e \u003cp\u003eKey generation and random numbers 38\u003c\/p\u003e \u003cp\u003eProtecting the Key  39\u003c\/p\u003e \u003cp\u003eSymmetric Algorithms Come in Different Flavors 40\u003c\/p\u003e \u003cp\u003eMaking a hash of it 40\u003c\/p\u003e \u003cp\u003eDefining blocks and streams 42\u003c\/p\u003e \u003cp\u003eWhich is better: Block or stream?  44\u003c\/p\u003e \u003cp\u003eIdentifying Symmetric Algorithms 45\u003c\/p\u003e \u003cp\u003eDes 45\u003c\/p\u003e \u003cp\u003eTriple DES  45\u003c\/p\u003e \u003cp\u003eIdea  46\u003c\/p\u003e \u003cp\u003eAes 46\u003c\/p\u003e \u003cp\u003eAsymmetric Keys 47\u003c\/p\u003e \u003cp\u003eRsa 48\u003c\/p\u003e \u003cp\u003eDiffie-Hellman (\u0026amp; Merkle)  49\u003c\/p\u003e \u003cp\u003ePgp 50\u003c\/p\u003e \u003cp\u003eElliptical Curve Cryptography  50\u003c\/p\u003e \u003cp\u003eWorking Together 52\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3: Deciding What You Really Need  53\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eJustifying the Costs to Management  53\u003c\/p\u003e \u003cp\u003eLong-term versus short-term  54\u003c\/p\u003e \u003cp\u003eTangible versus intangible results 55\u003c\/p\u003e \u003cp\u003ePositive ROI 55\u003c\/p\u003e \u003cp\u003eGovernment due diligence  60\u003c\/p\u003e \u003cp\u003eInsurers like it!  61\u003c\/p\u003e \u003cp\u003ePresenting your case  61\u003c\/p\u003e \u003cp\u003eDo You Need Secure Communications?  62\u003c\/p\u003e \u003cp\u003eSecure e-mail  62\u003c\/p\u003e \u003cp\u003eInstant Messaging (IM)  64\u003c\/p\u003e \u003cp\u003eSecure e-commerce  64\u003c\/p\u003e \u003cp\u003eOnline banking  66\u003c\/p\u003e \u003cp\u003eVirtual Private Networks (VPNs)  66\u003c\/p\u003e \u003cp\u003eWireless (In)security  68\u003c\/p\u003e \u003cp\u003eDo You Need to Authenticate Users? 69\u003c\/p\u003e \u003cp\u003eWho are your users?  70\u003c\/p\u003e \u003cp\u003eAuthentication tokens 71\u003c\/p\u003e \u003cp\u003eSmart cards 72\u003c\/p\u003e \u003cp\u003eJava tokens  73\u003c\/p\u003e \u003cp\u003eBiometrics 74\u003c\/p\u003e \u003cp\u003eDo You Need to Ensure Confidentiality and Integrity?  75\u003c\/p\u003e \u003cp\u003eProtecting Personal Data  75\u003c\/p\u003e \u003cp\u003eWhat’s It Gonna Cost?  77\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4: Locks and Keys  79\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eThe Magic Passphrase 80\u003c\/p\u003e \u003cp\u003eThe weakest link 81\u003c\/p\u003e \u003cp\u003eMental algorithms  82\u003c\/p\u003e \u003cp\u003eSafety first! 84\u003c\/p\u003e \u003cp\u003ePassphrase attacks  86\u003c\/p\u003e \u003cp\u003eDon’t forget to flush!  87\u003c\/p\u003e \u003cp\u003eThe Key Concept  88\u003c\/p\u003e \u003cp\u003eKey generation  89\u003c\/p\u003e \u003cp\u003eProtecting your keys  90\u003c\/p\u003e \u003cp\u003eWhat to do with your old keys 91\u003c\/p\u003e \u003cp\u003eSome cryptiquette  91\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart II: Public Key Infrastructure 93\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5: The PKI Primer  95\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhat Is PKI?  96\u003c\/p\u003e \u003cp\u003eCertificate Authorities (CAs)  97\u003c\/p\u003e \u003cp\u003eDigital Certificates  98\u003c\/p\u003e \u003cp\u003eDesktops, laptops, and servers  100\u003c\/p\u003e \u003cp\u003eKey servers 102\u003c\/p\u003e \u003cp\u003eRegistration Authorities (RAs) 103\u003c\/p\u003e \u003cp\u003eUses for PKI Systems 103\u003c\/p\u003e \u003cp\u003eCommon PKI Problems  105\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6: PKI Bits and Pieces  107\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCertificate Authorities 108\u003c\/p\u003e \u003cp\u003ePretenders to the throne 110\u003c\/p\u003e \u003cp\u003eRegistration Authorities  110\u003c\/p\u003e \u003cp\u003eCertificate Policies (CPs)  111\u003c\/p\u003e \u003cp\u003eDigital Certificates and Keys 112\u003c\/p\u003e \u003cp\u003eD’basing Your Certificates 113\u003c\/p\u003e \u003cp\u003eCertificate Revocation 114\u003c\/p\u003e \u003cp\u003ePicking the PKCS  115\u003c\/p\u003e \u003cp\u003ePKCS #1: RSA Encryption Standard 115\u003c\/p\u003e \u003cp\u003ePKCS #3: Diffie-Hellman Key Agreement Standard 115\u003c\/p\u003e \u003cp\u003ePKCS #5: Password-Based Cryptography Standard  115\u003c\/p\u003e \u003cp\u003ePKCS #6: Extended-Certificate Syntax Standard 116\u003c\/p\u003e \u003cp\u003ePKCS #7: Cryptographic Message Syntax Standard 116\u003c\/p\u003e \u003cp\u003ePKCS #8: Private-Key Information Syntax Standard 116\u003c\/p\u003e \u003cp\u003ePKCS #9: Selected Attribute Types  117\u003c\/p\u003e \u003cp\u003ePKCS #10: Certification Request Syntax Standard 117\u003c\/p\u003e \u003cp\u003ePKCS #11: Cryptographic Token Interface Standard 117\u003c\/p\u003e \u003cp\u003ePKCS #12: Personal Information Exchange Syntax Standard  118\u003c\/p\u003e \u003cp\u003ePKCS #13: Elliptic Curve Cryptography Standard  118\u003c\/p\u003e \u003cp\u003ePKCS #14: Pseudo-Random Number Generation Standard 118\u003c\/p\u003e \u003cp\u003ePKCS #15: Cryptographic Token Information Format Standard 118\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7: All Keyed Up!  119\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSo, What Exactly IS a Key?  120\u003c\/p\u003e \u003cp\u003eMaking a Key 120\u003c\/p\u003e \u003cp\u003eThe Long and Short of It  121\u003c\/p\u003e \u003cp\u003eRandomness in Keys Is Good 122\u003c\/p\u003e \u003cp\u003eStoring Your Keys Safely 123\u003c\/p\u003e \u003cp\u003eKeys for Different Purposes  124\u003c\/p\u003e \u003cp\u003eKeys and Algorithms  124\u003c\/p\u003e \u003cp\u003eOne Key; Two Keys  125\u003c\/p\u003e \u003cp\u003ePublic\/private keys  126\u003c\/p\u003e \u003cp\u003eThe magic encryption machine  127\u003c\/p\u003e \u003cp\u003eThe magic decryption machine  128\u003c\/p\u003e \u003cp\u003eSymmetric keys (again) 129\u003c\/p\u003e \u003cp\u003eTrusting Those Keys  129\u003c\/p\u003e \u003cp\u003eKey Servers 130\u003c\/p\u003e \u003cp\u003eKeeping keys up to date  131\u003c\/p\u003e \u003cp\u003ePolicies for keys  132\u003c\/p\u003e \u003cp\u003eKey escrow and key recovery 132\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart III: Putting Encryption Technologies to Work for You 135\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8: Securing E-Mail from Prying Eyes  137\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eE-Mail Encryption Basics  138\u003c\/p\u003e \u003cp\u003eS\/mime 138\u003c\/p\u003e \u003cp\u003ePgp 139\u003c\/p\u003e \u003cp\u003eDigital Certificates or PGP Public\/Private Key Pairs?  140\u003c\/p\u003e \u003cp\u003eWhat’s the diff? 140\u003c\/p\u003e \u003cp\u003eWhen should you use which? 141\u003c\/p\u003e \u003cp\u003eSign or encrypt or both?  141\u003c\/p\u003e \u003cp\u003eRemember that passphrase! 142\u003c\/p\u003e \u003cp\u003eUsing S\/MIME  142\u003c\/p\u003e \u003cp\u003eSetting up S\/MIME in Outlook Express  143\u003c\/p\u003e \u003cp\u003eBacking up your Digital Certificates  151\u003c\/p\u003e \u003cp\u003eFun and Games with PGP  153\u003c\/p\u003e \u003cp\u003eSetting up PGP  154\u003c\/p\u003e \u003cp\u003eDeciding on the options  156\u003c\/p\u003e \u003cp\u003ePlaying with your keyring  160\u003c\/p\u003e \u003cp\u003eSending and receiving PGP messages  162\u003c\/p\u003e \u003cp\u003ePGP in the enterprise 164\u003c\/p\u003e \u003cp\u003eOther Encryption Stuff to Try  164\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9: File and Storage Strategies  167\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhy Encrypt Your Data? 168\u003c\/p\u003e \u003cp\u003eEncrypted Storage Roulette  170\u003c\/p\u003e \u003cp\u003eSymmetric versus asymmetric? 171\u003c\/p\u003e \u003cp\u003eEncrypting in the air or on the ground?  173\u003c\/p\u003e \u003cp\u003eDealing with Integrity Issues 174\u003c\/p\u003e \u003cp\u003eMessage digest\/hash  174\u003c\/p\u003e \u003cp\u003eMACs  175\u003c\/p\u003e \u003cp\u003eHMACs 175\u003c\/p\u003e \u003cp\u003eTripwire 176\u003c\/p\u003e \u003cp\u003ePolicies and Procedures  177\u003c\/p\u003e \u003cp\u003eExamples of Encryption Storage  178\u003c\/p\u003e \u003cp\u003eMedia encryption 179\u003c\/p\u003e \u003cp\u003eEncrypting File System  180\u003c\/p\u003e \u003cp\u003eSecure e-mail 181\u003c\/p\u003e \u003cp\u003eProgram-specific encryption  181\u003c\/p\u003e \u003cp\u003eEncrypted backup  181\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10: Authentication Systems  183\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCommon Authentication Systems  185\u003c\/p\u003e \u003cp\u003eKerberos  185\u003c\/p\u003e \u003cp\u003eSsh  186\u003c\/p\u003e \u003cp\u003eRadius 187\u003c\/p\u003e \u003cp\u003eTacacs+  188\u003c\/p\u003e \u003cp\u003eAuthentication Protocols  188\u003c\/p\u003e \u003cp\u003eHow Authentication Systems Use Digital Certificates 190\u003c\/p\u003e \u003cp\u003eTokens, Smart Cards, and Biometrics 191\u003c\/p\u003e \u003cp\u003eDigital Certificates on a PC  191\u003c\/p\u003e \u003cp\u003eTime-based tokens 192\u003c\/p\u003e \u003cp\u003eSmartcard and USB Smartkeys 193\u003c\/p\u003e \u003cp\u003eBiometrics 194\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11: Secure E-Commerce  197\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSSL Is the Standard  198\u003c\/p\u003e \u003cp\u003eA typical SSL connection 199\u003c\/p\u003e \u003cp\u003eRooting around your certificates 201\u003c\/p\u003e \u003cp\u003eTime for TLS  203\u003c\/p\u003e \u003cp\u003eSetting Up an SSL Solution  204\u003c\/p\u003e \u003cp\u003eWhat equipment do I need?  205\u003c\/p\u003e \u003cp\u003eThe e-commerce manager’s checklist 206\u003c\/p\u003e \u003cp\u003eXML Is the New Kid on the Block 209\u003c\/p\u003e \u003cp\u003eGoing for Outsourced E-Commerce 210\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12: Virtual Private Network (VPN) Encryption  213\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eHow Do VPNs Work Their Magic?  214\u003c\/p\u003e \u003cp\u003eSetting Up a VPN  214\u003c\/p\u003e \u003cp\u003eWhat devices do I need?  215\u003c\/p\u003e \u003cp\u003eWhat else should I consider?  216\u003c\/p\u003e \u003cp\u003eDo VPNs affect performance? 216\u003c\/p\u003e \u003cp\u003eDon’t forget wireless! 217\u003c\/p\u003e \u003cp\u003eVarious VPN Encryption Schemes 217\u003c\/p\u003e \u003cp\u003ePPP and PPTP 217\u003c\/p\u003e \u003cp\u003eL2tp 218\u003c\/p\u003e \u003cp\u003eIPsec 218\u003c\/p\u003e \u003cp\u003eWhich Is Best?  220\u003c\/p\u003e \u003cp\u003eTesting, Testing, Testing  221\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 13: Wireless Encryption Basics  223\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhy WEP Makes Us Weep 224\u003c\/p\u003e \u003cp\u003eNo key management 225\u003c\/p\u003e \u003cp\u003ePoor RC4 implementation 225\u003c\/p\u003e \u003cp\u003eAuthentication problems 226\u003c\/p\u003e \u003cp\u003eNot everything is encrypted 226\u003c\/p\u003e \u003cp\u003eWEP Attack Methods 227\u003c\/p\u003e \u003cp\u003eFinding wireless networks 228\u003c\/p\u003e \u003cp\u003eWar chalking  228\u003c\/p\u003e \u003cp\u003eWireless Protection Measures  230\u003c\/p\u003e \u003cp\u003eLook for rogue access points  230\u003c\/p\u003e \u003cp\u003eChange the default SSIDs 230\u003c\/p\u003e \u003cp\u003eTurn on WEP 231\u003c\/p\u003e \u003cp\u003ePosition your access points well  232\u003c\/p\u003e \u003cp\u003eBuy special antennas 232\u003c\/p\u003e \u003cp\u003eUse a stronger encryption scheme  232\u003c\/p\u003e \u003cp\u003eUse a VPN for wireless networks  232\u003c\/p\u003e \u003cp\u003eEmploy an authentication system  233\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart IV: The Part of Tens  235\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 14: The Ten Best Encryption Web Sites  237\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eMat Blaze’s Cryptography Resource on the Web 237\u003c\/p\u003e \u003cp\u003eThe Center for Democracy and Technology 237\u003c\/p\u003e \u003cp\u003eSSL Review  238\u003c\/p\u003e \u003cp\u003eHow IPsec Works  238\u003c\/p\u003e \u003cp\u003eCode and Cipher 238\u003c\/p\u003e \u003cp\u003eCERIAS — Center for Education and Research in Information Assurance and Security 238\u003c\/p\u003e \u003cp\u003eThe Invisible Cryptologists — African Americans, WWII to 1956  239\u003c\/p\u003e \u003cp\u003eBruce Schneier 239\u003c\/p\u003e \u003cp\u003eNorth American Cryptography Archives  239\u003c\/p\u003e \u003cp\u003eRSA’s Crypto FAQ 239\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 15: The Ten Most Commonly Misunderstood Encryption Terms  241\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eMilitary-Grade Encryption  241\u003c\/p\u003e \u003cp\u003eTrusted Third Party 241\u003c\/p\u003e \u003cp\u003eX 509 Certificates 242\u003c\/p\u003e \u003cp\u003eRubber Hose Attack 242\u003c\/p\u003e \u003cp\u003eShared Secret  242\u003c\/p\u003e \u003cp\u003eKey Escrow  242\u003c\/p\u003e \u003cp\u003eInitialization Vector  243\u003c\/p\u003e \u003cp\u003eAlice, Bob, Carol, and Dave 243\u003c\/p\u003e \u003cp\u003eSecret Algorithm  243\u003c\/p\u003e \u003cp\u003eSteganography  244\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 16: Cryptography Do’s and Don’ts  245\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDo Be Sure the Plaintext Is Destroyed after a Document Is Encrypted  245\u003c\/p\u003e \u003cp\u003eDo Protect Your Key Recovery Database and Other Key Servers to the Greatest Extent Possible  246\u003c\/p\u003e \u003cp\u003eDon’t Store Your Private Keys on the Hard Drive of Your Laptop or Other Personal Computing Device 246\u003c\/p\u003e \u003cp\u003eDo Make Sure Your Servers’ Operating Systems Are “Hardened” before You Install Cryptological Systems on Them 246\u003c\/p\u003e \u003cp\u003eDo Train Your Users against Social Engineering  247\u003c\/p\u003e \u003cp\u003eDo Create the Largest Key Size Possible 247\u003c\/p\u003e \u003cp\u003eDo Test Your Cryptosystem after You Have It Up and Running 248\u003c\/p\u003e \u003cp\u003eDo Check the CERT Advisories and Vendor Advisories about Flaws and Weaknesses in Cryptosystems 248\u003c\/p\u003e \u003cp\u003eDon’t Install a Cryptosystem Yourself If You’re Not Sure What You Are Doing 248\u003c\/p\u003e \u003cp\u003eDon’t Use Unknown, Untested Algorithms 249\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 17: Ten Principles of “Cryptiquette”  251\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIf Someone Sends You an Encrypted Message, Reply in Kind  251\u003c\/p\u003e \u003cp\u003eDon’t Create Too Many Keys  251\u003c\/p\u003e \u003cp\u003eDon’t Immediately Trust Someone Just Because He\/She Has a Public Key 252\u003c\/p\u003e \u003cp\u003eAlways Back Up Your Keys and Passphrases 252\u003c\/p\u003e \u003cp\u003eBe Wary of What You Put in the Subject Line of Encrypted Messages  252\u003c\/p\u003e \u003cp\u003eIf You Lose Your Key or Passphrase, Revoke Your Keys as Soon as Possible  253\u003c\/p\u003e \u003cp\u003eDon’t Publish Someone’s Public Key to a Public Key Server without His\/Her Permission  253\u003c\/p\u003e \u003cp\u003eDon’t Sign Someone’s Public Key Unless You Have Reason To  253\u003c\/p\u003e \u003cp\u003eIf You Are Corresponding with Someone for the First Time, Send an Introductory Note Along with Your Public Key  254\u003c\/p\u003e \u003cp\u003eBe Circumspect in What You Encrypt 254\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 18: Ten Very Useful Encryption Products  255\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePGP: Pretty Good Privacy 255\u003c\/p\u003e \u003cp\u003eGaim  255\u003c\/p\u003e \u003cp\u003emadeSafe Vault 256\u003c\/p\u003e \u003cp\u003ePassword Safe 256\u003c\/p\u003e \u003cp\u003eKerberos  256\u003c\/p\u003e \u003cp\u003eOpenSSL and Apache SSL  256\u003c\/p\u003e \u003cp\u003eSafeHouse  257\u003c\/p\u003e \u003cp\u003eWebCrypt  257\u003c\/p\u003e \u003cp\u003ePrivacy Master  257\u003c\/p\u003e \u003cp\u003eAdvanced Encryption Package 257\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart V: Appendixes  259\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAppendix A: Cryptographic Attacks  261\u003c\/p\u003e \u003cp\u003eKnown Plaintext Attack 262\u003c\/p\u003e \u003cp\u003eChosen Ciphertext Attacks 262\u003c\/p\u003e \u003cp\u003eChosen Plaintext Attacks  263\u003c\/p\u003e \u003cp\u003eThe Birthday Attack 263\u003c\/p\u003e \u003cp\u003eMan-in-the-Middle Attack  263\u003c\/p\u003e \u003cp\u003eTiming Attacks  264\u003c\/p\u003e \u003cp\u003eRubber Hose Attack 264\u003c\/p\u003e \u003cp\u003eElectrical Fluctuation Attacks  265\u003c\/p\u003e \u003cp\u003eMajor Boo-Boos  265\u003c\/p\u003e \u003cp\u003eAppendix B: Glossary  267\u003c\/p\u003e \u003cp\u003eAppendix C: Encryption Export Controls  279\u003c\/p\u003e \u003cp\u003eIndex  283\u003c\/p\u003e “…a useful guide for anyone bamboozled by encryption…” (\u003ci\u003ePC Utilities\u003c\/i\u003e, June 2004) \u003cp\u003e“The reader can dip into it whenever the mood takes them…” (\u003ci\u003eMicroMart\u003c\/i\u003e, 29th April 2004)\u003c\/p\u003e Chey Cobb, CISSP, author of Network Security For Dummies, was Chief Security Officer for a National Reconnaissance Office (NRO) overseas location. She is a nationally recognized computer security expert.   Get expert advice on choosing and using cryptography products  \u003cp\u003eProtect yourself and your business from online eavesdroppers  its easier than you think!\u003c\/p\u003e \u003cp\u003eIf you were hoping for a flame-throwing watch or a flying car, were sorry  this isnt James Bonds equipment manual. Cryptography is a common-sense way to secure stuff on the Internet, and this friendly guidebook makes it easy to understand. Discover how you can protect information with keys, ciphers, PKIs, certificates, and more.\u003c\/p\u003e \u003cp\u003ePraise for Cryptography For Dummies\u003c\/p\u003e \u003cp\u003e\"Cryptography is absolutely fundamental to security, personal privacy and a trusted global economy. Everyone, and I mean everyone, should understand how to protect themselves and how cryptography is used to protect the worlds most important asset: information. Given her extraordinary background and practical experience in network security, Chey Cobb is uniquely qualified to simplify the mystique of cryptography for the average person.\"\u003cbr\u003e  Winn Schwartau, President, GetInsightU.Com and author \"Information Warfare\"and \"Pearl Harbor Dot Com\"\u003c\/p\u003e \u003cp\u003eDiscover how to:\u003c\/p\u003e \u003cul\u003e \u003cli\u003eAnalyze off-the-shelf encryption products\u003c\/li\u003e \u003cli\u003eDecide what type of security you need\u003c\/li\u003e \u003cli\u003eCreate and manage keys\u003c\/li\u003e \u003cli\u003eIssue digital signatures and certificates\u003c\/li\u003e \u003cli\u003eSet up SSL for e-commerce\u003c\/li\u003e \u003cli\u003eEnable wireless encryption\u003c\/li\u003e \u003c\/ul\u003e","brand":"For Dummies","offers":[{"title":"Default Title","offer_id":47989010170085,"sku":"NP9780764541889","price":39.99,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9780764541889.jpg?v=1761782420","url":"https:\/\/k12savings.com\/es\/products\/cryptography-for-dummies-isbn-9780764541889","provider":"K12savings","version":"1.0","type":"link"}