Mr Sandman: Time Lock Puzzles for Good and Evil - Matt Wixey
Description:
Explore the concept of timelock puzzles and their applications in cybersecurity in this 43-minute conference talk from OWASP AppSec EU 2018. Delve into the history of delayed execution techniques used by attackers to bypass security measures and how defenders implement similar methods to thwart bots and spammers. Discover how timelock puzzles, cryptographic constructs requiring specific computational effort or time to solve, can be weaponized for malicious purposes or utilized defensively. Examine case studies, novel timelock puzzle constructions, and their potential impact on malware detection and analysis. Learn about prevention strategies, including a heuristic model for generic detection of timelock puzzles, and explore the challenges of using these puzzles for beneficial purposes. Gain insights into the practicality of timelock puzzles in both offensive and defensive scenarios, and consider future research directions in this underexplored area of security research.