Live data from Hacker News

Tptacek's Review of "Practical Cryptography With Go"

gist.githubusercontent.com

161–170 of 255 posts

Re: Tptacek's Review of "Practical Cryptography With Go"

#161

Earlier quoted context omitted.

I feel comfortable with the idea of writing a book showing people how to break badly-implemented crypto designs, so much so that Sean, Alex, and I are in fact writing that book; it'll be a "pay-what-you-want" directly to a preferred charity. If anyone can point us to someone who will take our money to expertly typeset a giant text file, that would be helpful. I do not feel remotely comfortable with the idea of writin…

Any chance of just releasing it as big .txt balls, MaTaSaNo_Crypto_2_of_7.txt , with glorious ascii art at the top? You know, for old times' sake?

We have a different funny plan for releasing it. :)

Re: Tptacek's Review of "Practical Cryptography With Go"

#162
post #148

Earlier quoted context omitted.

When you are writing about a difficult subject, you should invite reviews from experts to vet your work.

I'm not disagreeing. I'm just pointing out that a critic is much less useful than an author.

That depends entirely on what type of book is being wrote. If I write a history textbook that goes into intricate detail about the Time Slip of 1662 and the Lost Years, and the eventual Realignment that resulted in the Great London Fire, am I being more useful than a critic who points out that my history textbook is full of factual inaccuracies?

Re: Tptacek's Review of "Practical Cryptography With Go"

#163
post #66

Earlier quoted context omitted.

You're being downvoted, but I agree that a greater amount of tact would have been warranted. Phrases like "I am not making this up", "argh!" and "huh?" add nothing to the review, but only serve to make it more personal, and I say this as a guy who also has very little tact.

There has been a cultural shift in recent years. None of tptacek's observations are adhominem. But there is now an expectation that one tone down the description of one's own reaction. I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation. (1) Sorry, but I have a right to an emotional reaction to your content and a right to describe it, especially if the r…

Personally, I feel the difference is in the writing style for the medium. For instance, while a critic might remark on how 'this is such a poor recommendation that it should inspire outrage in a security-conscious developer', someone writing a comment on the Internet may use 'this makes me feel like screaming'. The language is less 'refined' and seemingly more direct though it's really saying the same (appropriate for the medium).

My hypothesis is that people expect text that has no obvious signs of being an Internet comment to use the more 'serious' language and this case (an Internet comment that is a bit longer than usual) is being classified wrongly as a result.

Re: Tptacek's Review of "Practical Cryptography With Go"

#164

Earlier quoted context omitted.

There has been a cultural shift in recent years. None of tptacek's observations are adhominem. But there is now an expectation that one tone down the description of one's own reaction. I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation. (1) Sorry, but I have a right to an emotional reaction to your content and a right to describe it, especially if the r…

You're spot on with the cultural shift. To me, complaints about tone are for critiques that contain phrases like "fucking idiot" and "worthless waste of space" and other such direct insults or attacks. If something legitimately makes you stop and stare with your mouth hanging open, it is OK to say "this statement made me stop and stare with my mouth hanging open." Phrases like "I am not making this up" are reasonable…

> If something legitimately makes you stop and stare with your mouth hanging open, it is OK to say "this statement made me stop and stare with my mouth hanging open."

It's okay if you are writing a story about your personal reactions.

It's irrelevant if you are writing a serious critique, which should be about the content, not about your emotional response to it (assuming it is a critique of an informative work -- obviously, if you are critiquing something as a work of art intended to inspire emotional responses, writing about your response as some relevance.)

It's possible to blend the first kind of story with the second kind of critique, but you have to recognize the different roles of each, do it deliberately, and be exceptionally skilled (the set of people who can do this and produce something worth reading is a proper subset of the intersection of the sets of those who can write entertaining personal stories and those who can write valuable straight critiques.)

That being said, tptacek's review seems pretty focussed on substantive critique with very minimal emotional distractions, so while I disagree with the categorical defense of the individual statements at issue as being appropriate to a straight critique of an informative work, I also think that the charge that the tone was inappropriate and a barrier to reading is overblown considering the fairly minimal level at which distracting emotional descriptions are present in the review.

Re: Tptacek's Review of "Practical Cryptography With Go"

#165
post #154

Earlier quoted context omitted.

The point of responsible disclosure is that it limits the damage done to users of the system in question by reducing the window in which the flaw is known and the systems are unpatched. That doesn't apply for a book. Keeping the critique private for a week doesn't help the readers at all. In fact it harms them by keeping incorrect information in play and uncorrected for longer. Perhaps it softens the blow to the auth…

I agree with all your points. When I said treat this in a "responsible disclosure" method, I did really mean a grace period, for the authors sake[0]. Clearly the reasoning is not the same as a security issue, as you pointed out. I was trying to be a bit clever. My mistake. That all said, I still think we can treat each other better. Honest question: was it necessary to destroy it in such detail? Was it necessary for…

Yes, of the criticisms in that review, I think the "Crypto Box" one was among the most useful. He can fix that problem simply by renaming his library. The problem with calling it that is that there's also a library that provides a very carefully designed crypto_box: NaCl. NaCl was designed by someone who is simultaneously one of the world's best software security people and one of the best cryptographers. Repurposing the name like that is a little like a guy named Alan writing his own cipher and calling it "Alan's Encryption System".

Re: Tptacek's Review of "Practical Cryptography With Go"

#166
post #163

Earlier quoted context omitted.

There has been a cultural shift in recent years. None of tptacek's observations are adhominem. But there is now an expectation that one tone down the description of one's own reaction. I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation. (1) Sorry, but I have a right to an emotional reaction to your content and a right to describe it, especially if the r…

Personally, I feel the difference is in the writing style for the medium. For instance, while a critic might remark on how 'this is such a poor recommendation that it should inspire outrage in a security-conscious developer', someone writing a comment on the Internet may use 'this makes me feel like screaming'. The language is less 'refined' and seemingly more direct though it's really saying the same (appropriate fo…

Yes, I think this is something that his happening here. It's at least partially my fault, because once I had to pull the review into Gist, it was easy to post it on Twitter too, and so it took on a life I hadn't anticipated for it.

Re: Tptacek's Review of "Practical Cryptography With Go"

#167

Earlier quoted context omitted.

If I had written a book on implementing cryptography I've been throwing $20 bills at my monitor so that your book will start downloading, but it doesn't seem to be working. But really, you should write one.

No, I'm not even close to qualified to write that book.

Isn't this the problem, then? People here seem to think you are, and by reading you I get the impression that they're right. I don't believe that you won't write a book because you're not qualified: you just don't want to write one. And that's a good enough reason.

I think the community in general is very harsh towards anything related to cryptography. It's as if you shouldn't bother writing code unless you have mastery of the underlying mathematics while at the same time not bother with the maths unless you're an expert very-low-level-language programmer.

There is certainly a need to put forward blatant errors and potential flaws. But the general harshness is misguided I think. Tptacek, you simply said out loud what many thought, I'm sure. You'd make a lot of people happy if you wrote a book. Because you're still learning doesn't mean others can't learn from you.

Very subtly broken cryptography software is better than no cryptography software. And together we will learn to make it better.

Re: Tptacek's Review of "Practical Cryptography With Go"

#168
post #66

Earlier quoted context omitted.

You're being downvoted, but I agree that a greater amount of tact would have been warranted. Phrases like "I am not making this up", "argh!" and "huh?" add nothing to the review, but only serve to make it more personal, and I say this as a guy who also has very little tact.

There has been a cultural shift in recent years. None of tptacek's observations are adhominem. But there is now an expectation that one tone down the description of one's own reaction. I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation. (1) Sorry, but I have a right to an emotional reaction to your content and a right to describe it, especially if the r…

"I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation."

At 49, I see the exact opposite. Members of my generation tended to exhibit more tact and decorum. The urge to dress like a hobo, swear all the time, and flame everyone in sight is a classic overcompensation for years of helicopter parenting which forbade all of these things.

"In some cases, it's honesty."

In others, it's honesty used as a pretext for acting out.

Re: Tptacek's Review of "Practical Cryptography With Go"

#169
post #72
post #41

Earlier quoted context omitted.

This hardly makes any sense: - for the readers who already know the abbreviation, it's a waste of space and time - for readers who don't, the words won't tell them much either - Transport Layer Security tells you about nothing about what TLS really is - besides, for those who are really interested, they can always look it up on Wikipedia (that way, they will actually understand it).

> Transport Layer Security tells you about nothing about what TLS really is Doesn't it? Even a complete tech-illiterate can glean some meaning from the word "security".

And "Transport Layer" should ring a bell to anyone familiar with the OSI model (for example, a student that has taken an introductory course on network protocols).

Re: Tptacek's Review of "Practical Cryptography With Go"

#170
post #167

Earlier quoted context omitted.

No, I'm not even close to qualified to write that book.

Isn't this the problem, then? People here seem to think you are , and by reading you I get the impression that they're right. I don't believe that you won't write a book because you're not qualified : you just don't want to write one. And that's a good enough reason. I think the community in general is very harsh towards anything related to cryptography. It's as if you shouldn't bother writing code unless you have ma…

I don't know how to say this other than directly: you're wrong. I shouldn't write a book on how to design cryptosystems, because I'm not qualified to do it, and I'll get things wrong. I can barely write an HN comment on crypto without being corrected by 'pbsd and 'cperciva.

I am an odd duck, even for my odd little field: I'm a software security person who has spent a couple years getting decent at breaking crypto, and (weirdly) few people in my field do that, so I sound like more of an expert than I actually am.

Post reply on HN