Score:5

Status of whitebox cryptography in 2022

id flag

There has been a lot of discussion about whitebox cryptography in recent years. However, I haven't found any signs of real world applications using it.

  • Are there any real world IT solutions depending on whitebox cryptography as of 2022?
  • Is any kind of whitebox cryptography considered secure by any authority (NIST etc.) and openly used in some really critical areas (banking, military, ...)?
vojta avatar
id flag
Information Security might be more suitable for this question... Migrate it if you think so, please.
fgrieu avatar
ng flag
I think the Q can stay here. Whitebox cryptography is cryptography !
Score:3
in flag

Are there any real world IT solutions depending on whitebox cryptography as of 2022?

Yes, especially on mobile phones that don't contain a secure enclave or similar. There is a reason why e.g. Android tries to integrate more security by default though.

Is any kind of whitebox cryptography considered secure by any authority (NIST etc.) and openly used in some really critical areas (banking, military, ...)?

Yes, but that doesn't mean that it is easy to get whitebox cryptography accepted. Quite often the proprietary mechanisms are not secure enough, and the generic mechanisms from specialized parties are under big scrutiny by both white hat and black hat hackers. In that sense it is kind of a catch 22 situation: if you design it yourself you're doomed, and if you use a third party solution you will be doomed as well [EDIT: well "doomed" may be a bit of an exaggeration, but you know what I mean].

I'm not sure what NIST accepts or doesn't accept, but if they accept anything it won't be for banking, and I'd expect that what is acceptable to them will change in time. I see that they have certified a solution in the past, but that one has been marked as "historical" with a note that the solution should not be used by Federal Agencies. Not sure if they have certified anything lately.

Note that I'm not directly involved in white box cryptography at this time.

Maarten Bodewes avatar
in flag
I would very much support additional answers from persons that directly operate in this field.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.