Tptacek's Review of "Practical Cryptography With Go"
gist.githubusercontent.com
Tptacek's Review of "Practical Cryptography With Go"
1–10 of 255 posts
Re: Tptacek's Review of "Practical Cryptography With Go"
#2I read Schneier's & Ferguson's Practical Cryptography years ago, the only thing I remember about it is the "don't try this at home" message.
Re: Tptacek's Review of "Practical Cryptography With Go"
#3This is a good illustration of how, 1) crypto is hard 2) real-world cryptosystem design & implementation is hard and 3) teaching the aforementioned is hard. I read Schneier's & Ferguson's Practical Cryptography years ago, the only thing I remember about it is the "don't try this at home" message.
Was rather impressed...
Re: Tptacek's Review of "Practical Cryptography With Go"
#4Re: Tptacek's Review of "Practical Cryptography With Go"
#5This is a good illustration of how, 1) crypto is hard 2) real-world cryptosystem design & implementation is hard and 3) teaching the aforementioned is hard. I read Schneier's & Ferguson's Practical Cryptography years ago, the only thing I remember about it is the "don't try this at home" message.
I cannot take anyone who advocated MAC-then-Encrypt, in 2010, seriously (in the book Cryptography Engineering: Design Principles and Practical Applications by Niels Ferguson, Bruce Schneier, Tadayoshi Kohno).
The school of cryptography they subscribe to seems to be "crypto is black magic; this is tried and it works and it is pretty much secure because I feel it is secure; experience is everything; proofs can have bugs too" as opposed to a more principled, analytical, methodical, provable security.
This is especially problematic in pedagogical contexts, because the learners, by definition, do not have much experience or calibrated feelings, so they'll be lost or have to copy the design decisions of the authors without taking into account the contexts or that they might be flat wrong. That approach indeed implies the natural advice to someone who wants to learn will be "don't try it at home".
Re: Tptacek's Review of "Practical Cryptography With Go"
#6Re: Tptacek's Review of "Practical Cryptography With Go"
#7I'll take it on faith that Thomas really wrote this (it's his style), but would the real Thomas 'H' Ptacek please acknowledge that he indeed wrote this (it is labeled 'anonymous').
Re: Tptacek's Review of "Practical Cryptography With Go"
#8I'll take it on faith that Thomas really wrote this (it's his style), but would the real Thomas 'H' Ptacek please acknowledge that he indeed wrote this (it is labeled 'anonymous').
Re: Tptacek's Review of "Practical Cryptography With Go"
#9 AES - Advanced Encryption Standard
CBC - Cipher Block Chaining
PKCS - Public Key Cryptography Standards
SHA - Secure Hashing Algorithm
MAC - Message Authentication Code
PBKDF - Password-Based Key Derivation Function
NIST - National Institute of Standards and Technology
FIPS - Federal Information Processing Standard
KDF - Key derivation function
CTR - Counter Mode
RSA - Rivest Shamir Adleman (last names of each creator of the RSA algorithm)
OAEP - Optimal Asymmetric Encryption Padding
PSS - Probabilistic Signature Scheme
ECDSA - Elliptic Curve Digital Signature Algorithm
PS3 - Playstation 3?
DH - Diffie-Hellman key exchange
ECDH - Elliptic curve Diffie-Hellman key exchange
TLS - Transport Layer SecurityRe: Tptacek's Review of "Practical Cryptography With Go"
#10I'll take it on faith that Thomas really wrote this (it's his style), but would the real Thomas 'H' Ptacek please acknowledge that he indeed wrote this (it is labeled 'anonymous').
He actually posted this link yesterday as a comment: https://news.ycombinator.com/item?id=7581868