
1
00:00:00,260 --> 00:00:04,160
So, now we have a way, to ensure the 
confidentiality using Secure Socket 

2
00:00:04,160 --> 00:00:10,582
Layer, an public private key encryption. 
An the only question now remaining, is, 

3
00:00:10,582 --> 00:00:14,264
who are we talking to? 
And are we talking to that, server that 

4
00:00:14,264 --> 00:00:18,620
we think we're talking to? 
Are we really talking, to Amazon? 

5
00:00:18,620 --> 00:00:22,002
Are we really talking to Coursera? 
How do we know? 

6
00:00:22,002 --> 00:00:24,946
Now, you'll notice if you take a look at 
the top of your browser, perhaps right 

7
00:00:24,946 --> 00:00:28,426
now, even, you can take a look at the top 
of your browser. 

8
00:00:28,426 --> 00:00:31,554
And usually when it's indicating that you 
have a secure connection, you can click 

9
00:00:31,554 --> 00:00:37,577
on this and see some information. 
It's called the certificate information. 

10
00:00:37,577 --> 00:00:40,996
Okay? 
And so, https has the notion of a public 

11
00:00:40,996 --> 00:00:44,066
key. 
We retrieve the public key when we make 

12
00:00:44,066 --> 00:00:47,480
the connection. 
But there are two kinds of keys. 

13
00:00:47,480 --> 00:00:51,197
There are public keys that are just made 
up that are sent to us, and then there 

14
00:00:51,197 --> 00:00:55,032
are public keys that are signed and 
validated by a third-party certification 

15
00:00:55,032 --> 00:00:59,394
authority. 
So, this is a Coursera, and it is 

16
00:00:59,394 --> 00:01:03,850
certified by GoDaddy certification 
authority. 

17
00:01:03,850 --> 00:01:08,400
So, it's not just that we're getting the 
certificate from Coursera, we're actually 

18
00:01:08,400 --> 00:01:12,050
getting the certificate signed by 
GoDaddy. 

19
00:01:12,050 --> 00:01:16,340
That GoDaddy has, has, has checked the ID 
of Coursera and said, okay, you must be 

20
00:01:16,340 --> 00:01:22,610
the CEO of Coursera or I'm not going give 
you this signed, private key. 

21
00:01:22,610 --> 00:01:26,758
So, it's a process to get private keys 
signed and it's a way to make sure you 

22
00:01:26,758 --> 00:01:31,710
are talking to who you think you're 
talking to. 

23
00:01:31,710 --> 00:01:36,585
So, this is called digital certificates, 
also known as sort of signed private 

24
00:01:36,585 --> 00:01:40,500
keys. 
Now if we go back and we talk about the 

25
00:01:40,500 --> 00:01:42,860
integrity. 
Right? 

26
00:01:42,860 --> 00:01:45,324
We want to know who we're talking about, 
and so we have this notion of a 

27
00:01:45,324 --> 00:01:48,630
signature. 
A signature's a way that you know that 

28
00:01:48,630 --> 00:01:52,936
you're talking to who you're talking to. 
So, for example, like if a guy comes to 

29
00:01:52,936 --> 00:01:57,572
your office and says, hi, I'm Doctor 
Chuck, got like a beard and some white 

30
00:01:57,572 --> 00:02:01,244
hair. 
You can say, hey, if you're really Doctor 

31
00:02:01,244 --> 00:02:05,497
Chuck, show me your tattoo. 
And now you know, that very few people 

32
00:02:05,497 --> 00:02:09,710
will look like this and have this tattoo. 
Right? 

33
00:02:09,710 --> 00:02:14,730
So, this is my private key and this is my 
signature of my private key. 

34
00:02:14,730 --> 00:02:18,024
This is like my message digest so, so 
people won't have this tattoo if they 

35
00:02:18,024 --> 00:02:22,155
claim to be Doctor Chuck. 
So, this is Doctor Chuck, this is my 

36
00:02:22,155 --> 00:02:26,669
message digest. 
So, there's a difference between a 

37
00:02:26,669 --> 00:02:30,634
private key and a private key that's been 
certified by one of these designated 

38
00:02:30,634 --> 00:02:34,854
third parties. 
These designated third parties are called 

39
00:02:34,854 --> 00:02:38,705
certificate authorities. 
Now you could say, I'm a certificate 

40
00:02:38,705 --> 00:02:42,993
authority, well some certificate 
authorities are more better certificate 

41
00:02:42,993 --> 00:02:47,850
authorities than others, okay. 
So, they're a trusted third party. 

42
00:02:49,240 --> 00:02:53,327
And so, how do they start, well, some are 
more trusted than others, and the more we 

43
00:02:53,327 --> 00:02:59,010
trust them, they kind of all work out. 
So, it's not everybody, you can't become 

44
00:02:59,010 --> 00:03:03,660
a trusted authority so one of the many 
trusted authorities. 

45
00:03:03,660 --> 00:03:06,170
And one of the oldest ones and one of the 
more popular ones. 

46
00:03:06,170 --> 00:03:09,858
And one of the more expensive ones. 
It's pretty expensive to get your 

47
00:03:09,858 --> 00:03:13,580
certificate signed, it can be as 
inexpensive as a couple hundred dollars. 

48
00:03:13,580 --> 00:03:16,310
It can be thousands of dollars to get a 
certificate signed. 

49
00:03:17,920 --> 00:03:21,504
And their sign is one of the oldest and 
most well respected of the certificate 

50
00:03:21,504 --> 00:03:25,302
authorities. 
So, the idea is, is that, I have this 

51
00:03:25,302 --> 00:03:29,110
website called online.drchuck.com, where 
I teach Python classes and do various 

52
00:03:29,110 --> 00:03:33,028
other things. 
And I wanted a secure certificate because 

53
00:03:33,028 --> 00:03:37,120
I would be handling people's data. 
And I wanted to, to be respectable and 

54
00:03:37,120 --> 00:03:42,840
have a secure certificate. 
So, I had a public and a private key and 

55
00:03:42,840 --> 00:03:46,800
then I sent it to a certificate authority 
and I paid them money and then they send 

56
00:03:46,800 --> 00:03:52,270
me back a signed private key, okay. 
So, this is a, now, now you might say, 

57
00:03:52,270 --> 00:03:55,624
oh, this is kind of evil. 
Or, this is really expensive because all 

58
00:03:55,624 --> 00:03:58,963
they really are doing is like, changing a 
few bits in the, in my private key or 

59
00:03:58,963 --> 00:04:04,014
adding a few bits to my private key. 
But they have a lot of responsibility, 

60
00:04:04,014 --> 00:04:06,850
and the good ones have a lot of 
credibility. 

61
00:04:06,850 --> 00:04:10,700
So, they don't want to lose information. 
They gotta spend some time validating 

62
00:04:10,700 --> 00:04:14,850
identity, saying okay are you really the 
owner of drchuck.com. 

63
00:04:14,850 --> 00:04:18,998
They're not going to hand a certificate, 
a signed certificate for drchuck.com to 

64
00:04:18,998 --> 00:04:23,790
anybody, except the true owner, and so 
they spend some time. 

65
00:04:23,790 --> 00:04:27,222
Checking to make sure that it's the true 
owner, and they do this by looking at the 

66
00:04:27,222 --> 00:04:31,050
registration data at drchuck.com, et 
cetera et cetera. 

67
00:04:31,050 --> 00:04:34,246
So, there is a cost of verifying all this 
identity, kind of like signature track on 

68
00:04:34,246 --> 00:04:36,938
Coursera. 
And that's kind of what's going on on 

69
00:04:36,938 --> 00:04:40,798
signature track of Coursera. 
There's a difference between a 

70
00:04:40,798 --> 00:04:45,982
certificate and a certificate that 
Coursera is going to assert, that we have 

71
00:04:45,982 --> 00:04:50,601
verified the identity. 
And the cost is in the verification of 

72
00:04:50,601 --> 00:04:54,180
the identity. 
So, certificate authorities are charging 

73
00:04:54,180 --> 00:04:57,161
Amazon. 
But then ensuring that they don't 

74
00:04:57,161 --> 00:05:01,614
mistakenly give the Amazon.com 
certificate, to a random bad guy because 

75
00:05:01,614 --> 00:05:06,756
if they did. 
That bad guy could pretend to be 

76
00:05:06,756 --> 00:05:10,717
Amazon.com. 
So then you might ask, who decides which 

77
00:05:10,717 --> 00:05:16,312
of the certificate authorities to trust? 
We use the certificate authorities to 

78
00:05:16,312 --> 00:05:20,856
decide whether or not to trust Amazon.com 
or Coursera.org or drchuck.com or 

79
00:05:20,856 --> 00:05:24,988
whatever. 
How do we decide which of the certificate 

80
00:05:24,988 --> 00:05:29,840
authorities we're going to trust? 
Well, it turns out that Apple, Microsoft, 

81
00:05:29,840 --> 00:05:33,181
and Linux and other operating system 
vendors. 

82
00:05:33,181 --> 00:05:37,149
Pre-install at the moment that you're 
either purchasing your computer or 

83
00:05:37,149 --> 00:05:42,605
installing your operating system. 
Part of that operating system is actually 

84
00:05:42,605 --> 00:05:47,850
a list of the public keys of the chosen 
certificate authority. 

85
00:05:47,850 --> 00:05:51,411
So, if you look deep enough inside your 
computer. 

86
00:05:51,411 --> 00:05:56,091
This is my Mac, you can see the companies 
that have been included by Apple as the 

87
00:05:56,091 --> 00:06:02,218
manufacturer of the operating system. 
And so you see that Verisign is one of 

88
00:06:02,218 --> 00:06:07,396
those companies that has been 
pre-included in Apple Macintosh. 

89
00:06:07,396 --> 00:06:12,700
Which means that a certificate from 
Verisign is going to be known, right? 

90
00:06:12,700 --> 00:06:14,250
So, let's, so let's look a li, a little 
bit more. 

91
00:06:14,250 --> 00:06:19,010
So, so these come, your browsers and your 
operating systems come with pre built in 

92
00:06:19,010 --> 00:06:25,314
public key certificates for certain 
certificate authorities like Verisign. 

93
00:06:25,314 --> 00:06:29,574
Now that's a lot of trust that Apple, 
Microsoft, and Linux have placed in 

94
00:06:29,574 --> 00:06:32,416
Verisign. 
And that's because over the years 

95
00:06:32,416 --> 00:06:35,982
Verisign has earned that trust. 
It says, Verisign doesn't just give out 

96
00:06:35,982 --> 00:06:40,155
certificates without checking, right. 
If Verisign gave out an amazon.com 

97
00:06:40,155 --> 00:06:44,921
certificate to somebody without checking, 
they would lose a lot of credibility. 

98
00:06:44,921 --> 00:06:48,661
And then Microsoft would like, take them 
out, right, say, well, Verisign seems to 

99
00:06:48,661 --> 00:06:52,016
be kind of sleazy, they seem not to be 
able to to handle their security, but 

100
00:06:52,016 --> 00:06:55,968
they have. 
So, they remain in there, and it's kind 

101
00:06:55,968 --> 00:07:00,652
of an interesting thing where they are 
motivated to keep their security high. 

102
00:07:00,652 --> 00:07:03,946
They are motivated to do a good job 
because the moment that they fail, they 

103
00:07:03,946 --> 00:07:09,108
lose a lot of credibility and respect. 
Their value, the Verisign brand is all 

104
00:07:09,108 --> 00:07:14,442
the respect we have for Verisign. 
So, so, so, we mentioned public, private 

105
00:07:14,442 --> 00:07:18,257
key encryption. 
We have the public key that goes across 

106
00:07:18,257 --> 00:07:23,821
and I'm about to type my credit card in. 
And so, the problem now we're going to 

107
00:07:23,821 --> 00:07:27,631
solve is, I'm, is this really Amazon's 
key? 

108
00:07:27,631 --> 00:07:32,447
Is it really Amazon's public-key? 
I mean I'm, I got a public-key from the, 

109
00:07:32,447 --> 00:07:38,680
across this connection I made to a server 
and it claims that it's amazon.com. 

110
00:07:38,680 --> 00:07:42,020
But, do I believe that it says it's 
amazon.com? 

111
00:07:42,020 --> 00:07:46,470
So, that's the integrity thing, that's 
the secure, that's the, do I believe it? 

112
00:07:46,470 --> 00:07:50,557
Is it really got the Verisign tattoo in 
addition to the amazon.com that it, it's, 

113
00:07:50,557 --> 00:07:55,240
it represents that it's amazon.com's 
public key. 

114
00:07:55,240 --> 00:07:57,960
So, we can also use public keys to do 
signing. 

115
00:07:57,960 --> 00:08:04,080
And, and basically Verisign has a public 
and private key for Verisign. 

116
00:08:04,080 --> 00:08:06,955
The public key for Verisign is sitting in 
your browser right now. 

117
00:08:06,955 --> 00:08:11,710
And they use, they do an encryption much 
like the message digest. 

118
00:08:11,710 --> 00:08:15,430
They do an encryption of Amazon's 
certificate, and then sort of create a 

119
00:08:15,430 --> 00:08:21,200
digest and then add that digest to it. 
So, the certificate says I'm Amazon.com, 

120
00:08:21,200 --> 00:08:27,512
and later it says, oh yes, and Verisign 
signed this with Verisign's private key. 

121
00:08:27,512 --> 00:08:31,430
Okay, so Verisign's private key is used 
to sign Amazon. 

122
00:08:31,430 --> 00:08:36,130
This is probably easiest if I just show 
you sort of a video. 

123
00:08:36,130 --> 00:08:37,936
Wait, oop, I'm going the wrong way, am I 
going the wrong way? 

124
00:08:37,936 --> 00:08:42,212
What's going on here? 
I'm going the wrong way. 

125
00:08:42,212 --> 00:08:44,634
Yeah, I'm going the wrong way. 
Okay. 

126
00:08:44,634 --> 00:08:48,140
So, here we go, we're going backwards. 
Here's how it works. 

127
00:08:49,450 --> 00:08:54,925
this is how Amazon gets a public key 
signed by Verisign. 

128
00:08:54,925 --> 00:08:57,738
Right? 
So, in the beginning Verisign makes a 

129
00:08:57,738 --> 00:09:02,783
public and a private key. 
Somewhere in a bunker, and they store the 

130
00:09:02,783 --> 00:09:06,856
private key. 
And they'll, sometime you can read up on 

131
00:09:06,856 --> 00:09:11,416
how many, how much effort they go to 
storing the private key and then they 

132
00:09:11,416 --> 00:09:19,133
hand the public key to Apple. 
Microsoft and Linux and then they bundle 

133
00:09:19,133 --> 00:09:24,616
that in with your laptop. 
So, your laptop that you buy, you walk 

134
00:09:24,616 --> 00:09:30,650
out and you have a laptop and it's got 
public keys in it from the vendor. 

135
00:09:30,650 --> 00:09:34,890
Now Amazon says, you know what, I'd like 
to do some commerce. 

136
00:09:34,890 --> 00:09:42,360
And I would like to be able to use SSL 
and have a certified private key. 

137
00:09:42,360 --> 00:09:48,070
So, then what Amazon does. 
Is Amazon inside of its servers generates 

138
00:09:48,070 --> 00:09:53,849
a pair, a public-private key pair. 
So, this private key is not leaving 

139
00:09:53,849 --> 00:09:57,390
Amazon servers. 
It takes a while, it takes minutes 

140
00:09:57,390 --> 00:10:01,470
sometimes to generate the right random, 
sufficiently random public and private 

141
00:10:01,470 --> 00:10:04,604
key. 
Like looking at all the large prime 

142
00:10:04,604 --> 00:10:09,760
numbers and then picking one and then, 
bang, making a public and private key. 

143
00:10:09,760 --> 00:10:16,110
Then what Amazon does at that point, is 
it transports its public key to Verisign. 

144
00:10:16,110 --> 00:10:19,970
Now, during that transport, it might, 
eave might've seen it. 

145
00:10:19,970 --> 00:10:23,740
But it's okay, because it's just, it's 
just a public key, right? 

146
00:10:23,740 --> 00:10:26,964
So, it's just a public key and so it 
actually can be sent across the internet 

147
00:10:26,964 --> 00:10:30,358
and it's most commonly sent across the 
internet. 

148
00:10:30,358 --> 00:10:33,686
Like when I got the online.drchuck.com 
certificates, we just typed it in and 

149
00:10:33,686 --> 00:10:36,806
sent it, because if you get a hold of the 
public key, all it means is you can 

150
00:10:36,806 --> 00:10:40,710
encrypt. 
It doesn't mean you can decrypt. 

151
00:10:40,710 --> 00:10:46,191
So, then what happens is inside of 
Verisign's servers, Verisign computes a 

152
00:10:46,191 --> 00:10:52,692
message digest using its public, it, it, 
it, it's private key. 

153
00:10:52,692 --> 00:10:55,242
Right? 
And then it adds basically a signature 

154
00:10:55,242 --> 00:10:59,652
that says, oh, here's Amazon's public key 
that I received from Amazon, verified the 

155
00:10:59,652 --> 00:11:04,314
identity of the person, and now I have 
signed it Mr. 

156
00:11:04,314 --> 00:11:08,560
Verisign. 
I've signed it. 

157
00:11:08,560 --> 00:11:13,320
And that of course is just like message 
digest-like information that is appended 

158
00:11:13,320 --> 00:11:19,589
to the bits of the public key. 
Then that public key with signature is 

159
00:11:19,589 --> 00:11:26,150
sent back. 
Bundled together and sent back to Amazon. 

160
00:11:26,150 --> 00:11:29,305
And now Amazon has not just any old 
public key. 

161
00:11:29,305 --> 00:11:33,819
It has a public key that says I am 
Amazon.com and Verisign is now asserting 

162
00:11:33,819 --> 00:11:40,305
that I am really who I am. 
Now, an, an, again, so eve saw that one. 

163
00:11:40,305 --> 00:11:43,680
Who cares? 
It's just a public key. 

164
00:11:43,680 --> 00:11:50,358
There's nothing about the VeriSign 
private key, it never left the VeriSign 

165
00:11:50,358 --> 00:11:54,340
servers. 
The signature is public information. 

166
00:11:54,340 --> 00:12:00,060
You can, use the, the Verisign public key 
to verify that the signature is right. 

167
00:12:00,060 --> 00:12:04,140
But you can't forge the signature. 
So Eve can look at that. 

168
00:12:04,140 --> 00:12:06,760
Eve could look going this way, Eve can 
look that way. 

169
00:12:06,760 --> 00:12:11,160
Eve gets nothing. 
Eve gets nothing. 

170
00:12:11,160 --> 00:12:16,860
So, Amazon now has a signed, and 
certified private key. 

171
00:12:16,860 --> 00:12:23,158
Then what happens, is sooner or later, 
many hours, many days, many months later, 

172
00:12:23,158 --> 00:12:29,554
you decide on your laptop, remember this 
is you, opps. 

173
00:12:29,554 --> 00:12:35,413
This is you, you want to buy some shoes, 
so you connect to Amazon.com with your 

174
00:12:35,413 --> 00:12:43,416
browser, with an https connection. 
And then what happens is, Amazon sends 

175
00:12:43,416 --> 00:12:50,500
you it's public key and Eve of course is 
eaves dropping all the time. 

176
00:12:50,500 --> 00:12:54,010
Eve sees it goes by. 
It's worthless. 

177
00:12:54,010 --> 00:12:56,545
Right? 
It's worthless because it's just the 

178
00:12:56,545 --> 00:12:59,450
encryption key. 
It's not the decryption key. 

179
00:12:59,450 --> 00:13:01,970
The fact that it's signed, it sees that 
but it can't do anything with that 

180
00:13:01,970 --> 00:13:06,761
information. 
Now, within your laptop, within your 

181
00:13:06,761 --> 00:13:14,185
laptop, you have from the vendor the 
Verisign public key, from Macintosh, or 

182
00:13:14,185 --> 00:13:20,753
Apple, or whatever. 
So, you can look with this, oh, come 

183
00:13:20,753 --> 00:13:24,950
back, you can look with this public key 
at that signature. 

184
00:13:24,950 --> 00:13:28,366
And just like we did with the message 
digest before, we can go, Yep, that's 

185
00:13:28,366 --> 00:13:32,233
good, that really had to have been signed 
by Verisign. 

186
00:13:32,233 --> 00:13:35,481
And if your computer is really 
conservative, it can actually go check 

187
00:13:35,481 --> 00:13:39,572
with Verisign, send it up and say hey, 
did you verify this?. 

188
00:13:39,572 --> 00:13:43,004
And Verisign can verify it too, but you 
actually don't need to connect, because 

189
00:13:43,004 --> 00:13:46,556
you have the public key. 
The only way that the, the you know, 

190
00:13:46,556 --> 00:13:49,904
whatever that message digest could be 
right would be, is if Verisign, it's 

191
00:13:49,904 --> 00:13:54,440
private key, was used to generate the 
message digest. 

192
00:13:54,440 --> 00:13:59,392
Just like we do Santa in the other one. 
The Santa is really simple, but it's the 

193
00:13:59,392 --> 00:14:04,598
same basic mechanism. 
This is verifiable that it came from this 

194
00:14:04,598 --> 00:14:08,026
private key. 
Now, if somebody broke in and stole the 

195
00:14:08,026 --> 00:14:11,899
private key, that's a different story. 
But if the private key is safe and 

196
00:14:11,899 --> 00:14:15,189
secure, hasn't been compromised, the only 
way to generate that message digest is to 

197
00:14:15,189 --> 00:14:20,718
be in possession of the private key. 
So, now you are in a position where you 

198
00:14:20,718 --> 00:14:26,687
are in a good mood, right? 
You see an https, you can pop that little 

199
00:14:26,687 --> 00:14:29,740
thing and say that was signed by 
Verisign. 

200
00:14:29,740 --> 00:14:34,540
You can be assured that Verisign is 
asserting that that key came really, that 

201
00:14:34,540 --> 00:14:40,119
public key came from Amazon. 
And now it is time to encrypt your Visa 

202
00:14:40,119 --> 00:14:44,860
card and send it over encrypted 
connection to Amazon. 

203
00:14:45,940 --> 00:14:47,884
Okay? 
Because you won't send your encrypted 

204
00:14:47,884 --> 00:14:51,264
thing, your, your, your, you won't send 
it unless you believe that the https is 

205
00:14:51,264 --> 00:14:54,156
proper. 
And your browser will pop-up a little 

206
00:14:54,156 --> 00:14:57,622
pop-up and say, wait a sec, this 
certificate looks a little funky. 

207
00:14:57,622 --> 00:15:00,704
It claims to be from Amazon.com, but it's 
not signed by one of the signatures that 

208
00:15:00,704 --> 00:15:05,326
I believe in. 
So, you send your data, it is encrypted 

209
00:15:05,326 --> 00:15:09,056
and Eve is watching, right? 
Eve is always watching, but because it's 

210
00:15:09,056 --> 00:15:12,388
encrypted with a public key, unless Eve 
has supercomputers in a couple of months, 

211
00:15:12,388 --> 00:15:16,330
there is nothing that Eve can do. 
And then of course, Amazon decrypts it 

212
00:15:16,330 --> 00:15:22,286
using the private key. 
So, the private key comes in, and let me 

213
00:15:22,286 --> 00:15:26,805
redo that. 
Alright, so in it comes. 

214
00:15:26,805 --> 00:15:32,145
Eve watches, but it's helpless because 
they don't have enough computers. 

215
00:15:32,145 --> 00:15:37,450
Eve doesn't have enough computers an your 
key is large enough. 

216
00:15:37,450 --> 00:15:41,546
So, Amazon, then takes this private key, 
an uses that to decrypt it, an ends up 

217
00:15:41,546 --> 00:15:46,513
with your plain text again. 
So, if you think this whole thing 

218
00:15:46,513 --> 00:15:49,201
through, this, Eve was watching the whole 
time. 

219
00:15:49,201 --> 00:15:50,473
We sent a public key. 
We signed and returned a public key. 

220
00:15:50,473 --> 00:15:53,820
Then we sent the public key to your 
laptop. 

221
00:15:53,820 --> 00:15:57,992
We verified the public key. 
And the whole time Eve is sort of 

222
00:15:57,992 --> 00:16:04,579
watching all this information and she is 
powerless to break it. 

223
00:16:06,690 --> 00:16:12,964
Pretty dang clever, if you ask me. 
And we can thank Diffy, Helmon and Merkel 

224
00:16:12,964 --> 00:16:16,020
for that. 
Pretty darn clever. 

225
00:16:16,020 --> 00:16:21,011
Because Eve sees it all. 
Just think what would happened if like, 

226
00:16:21,011 --> 00:16:26,400
the Germans had this in World War II. 
It would've been pretty cool. 

227
00:16:26,400 --> 00:16:29,118
Course, they didn't have computers, so, 
it'd have been difficult. 

228
00:16:29,118 --> 00:16:32,370
I don't know. 
Too much to think about right now, okay. 

229
00:16:32,370 --> 00:16:35,808
Continuing on. 
So, what we have, is we have this thing 

230
00:16:35,808 --> 00:16:41,268
called the certificate authority which is 
a trusted, third-party that signs these 

231
00:16:41,268 --> 00:16:47,050
certificates, right? 
And so it's the entity that issues 

232
00:16:47,050 --> 00:16:52,220
digital signatures on public keys. 
So, that we the public have a way of 

233
00:16:52,220 --> 00:16:58,160
validating that an Amazon.com certificate 
really came from Amazon.com. 

234
00:16:58,160 --> 00:17:01,231
So, if you then add this all together, 
right? 

235
00:17:01,231 --> 00:17:06,350
If you add this all together, we have 
basic public, private key encryption. 

236
00:17:07,820 --> 00:17:11,360
That make sure that, this data can move 
across the internet, out of your 

237
00:17:11,360 --> 00:17:15,920
computer, out, back into the next one, 
all encrypted. 

238
00:17:15,920 --> 00:17:18,140
That's just public private that does 
that. 

239
00:17:18,140 --> 00:17:21,780
An then we have this third party, 
certificate authority, that your 

240
00:17:21,780 --> 00:17:27,230
application, can use, to validate the 
certificate, that comes out. 

241
00:17:27,230 --> 00:17:31,003
An so, the combination of SSL, or the 
Secure Sockets Layer. 

242
00:17:31,003 --> 00:17:35,287
And the certificate authority gives us 
high confidence, that when we're talking 

243
00:17:35,287 --> 00:17:39,190
to something we know we're really talking 
to it. 

244
00:17:39,190 --> 00:17:43,580
So, it's pretty non intrusive security. 
If your browser pops up with a little 

245
00:17:43,580 --> 00:17:46,570
popup message, that means it's got a 
certificate that it has no certificate of 

246
00:17:46,570 --> 00:17:50,518
authority to validate. 
And that's not a good time to be typing 

247
00:17:50,518 --> 00:17:54,235
in sensitive information, unless you know 
exactly what's going on. 

248
00:17:54,235 --> 00:17:58,255
So, that sort of brings us to the 
conclusion of this, these last couple of 

249
00:17:58,255 --> 00:18:02,482
lectures have been about message 
confidentially. 

250
00:18:02,482 --> 00:18:06,175
And that's protecting the contents from 
being revealed. 

251
00:18:06,175 --> 00:18:08,560
We use encrypting and decrypting for 
that. 

252
00:18:08,560 --> 00:18:12,470
And then we have message digest. 
And, sur, to sign things. 

253
00:18:12,470 --> 00:18:15,374
We've signed messages, we've signed 
certificates, we've signed many things, 

254
00:18:15,374 --> 00:18:19,053
and those are important. 
And we talked about both sort of, shared 

255
00:18:19,053 --> 00:18:22,178
key, and secret key, where you have to 
get together. 

256
00:18:22,178 --> 00:18:25,238
And agree on a key which is a symmetric 
key that's used for encrypting and 

257
00:18:25,238 --> 00:18:28,102
decrypting. 
And then you have the public private key 

258
00:18:28,102 --> 00:18:30,941
which is the asymmetric. 
Which is one key is used for encrypting 

259
00:18:30,941 --> 00:18:35,102
and the other key is used for decrypting. 
And you can freely show the encrypting 

260
00:18:35,102 --> 00:18:38,280
key because it gives very little 
information. 

261
00:18:38,280 --> 00:18:42,620
Although, it is mathematically possible, 
but difficult to decrypt public private 

262
00:18:42,620 --> 00:18:46,189
key message. 
So, that kinds of suns up, kind of sums 

263
00:18:46,189 --> 00:18:51,640
up our lecture on public private keys and 
I hope you find it valuable. 

264
00:18:51,640 --> 00:18:52,210
See you on the net. 

