Live data from Hacker News

Tptacek's Review of "Practical Cryptography With Go"

gist.githubusercontent.com

191–200 of 255 posts

Re: Tptacek's Review of "Practical Cryptography With Go"

#191
post #163

Earlier quoted context omitted.

Personally, I feel the difference is in the writing style for the medium. For instance, while a critic might remark on how 'this is such a poor recommendation that it should inspire outrage in a security-conscious developer', someone writing a comment on the Internet may use 'this makes me feel like screaming'. The language is less 'refined' and seemingly more direct though it's really saying the same (appropriate fo…

Yes, I think this is something that his happening here. It's at least partially my fault, because once I had to pull the review into Gist, it was easy to post it on Twitter too, and so it took on a life I hadn't anticipated for it.

I don't think you're at fault for anything. There's nothing inappropriate in your review.

It's ridiculous to simultaneously say that a piece of writing devoid of context is being classified in a certain way and to say that it contains that's inappropriate for that classification.

The mere presence of phrases like "I am not making this up" tells you that this piece is not intended to be too serious. To say that it's intended seriously but contains non-serious language is a flat-out contradiction.

It could make sense if it was published in some context, like a serious blog or a news site or something, which implied seriousness. But it's a naked text file on the internet. It doesn't have to take a serious tone.

Re: Tptacek's Review of "Practical Cryptography With Go"

#192
post #189

After I finished reading this review, I came to check out the HN comments knowing that the tone would be the subject of the top comments. When did this community become more concerned with tone than correctness? The top of this thread is filled with people saying that the tone is bad, it's unproductive, it's unnecessary, etc. Yet nobody seems concerned about the published book filled with bad information that a lot o…

Perhaps the reason people are not commenting on the correctness as much is that it is, broadly, correct. It's quite difficult to add to a discussion when it's already right - there's no debate to be had.

In which case, in a sane technical community, I would expect this thread to contain few comments.

Re: Tptacek's Review of "Practical Cryptography With Go"

#193
post #91
post #89

Earlier quoted context omitted.

The problem with regulation is that one must first establish who is capable of regulating correctly. There's no such thing as abstract regulation that simply exists. The entities that would most likely do the regulating already exist, but I'm unconvinced any of them would actually improve the situation. For instance, see http://blog.cr.yp.to/20140411-nist.html . What real group of people could really regulate cryptog…

I failed to express myself well. I'm not suggesting that all crypto is immediately regulated, that is completely infeasible. I'm just point out that regulation in general, over all domains, isn't inherently bad. There is actually some regulation in this space. FIPS compliance, PCI DSS etc.. It's just not as wide reaching as something like the FAA for aeroplanes.

"I'm just point out that regulation in general, over all domains, isn't inherently bad."

Very few people seriously argue that. (Non-zero, but very few.) I'm a libertarian and I wouldn't seriously argue that. It's mostly a strawman. (I advise anyone who makes routine use of that strawman to stop, and read more carefully whenever they feel tempted to use it again, but that's another post.)

My point is that we aren't talking about "regulation in general", we're talking about "regulation in cryptography", and it's a logical and/or cognitive error to fall back to a general case when one is trying to consider a specific case. If we're going to regulate cryptography, how are we going to regulate it? "In the general case regulators" don't exist. The closest entities we have now that would almost certainly become the regulators show few to no signs of being worthy of the task. This is a serious problem to be addressed without falling back to "general cases".

Re: Tptacek's Review of "Practical Cryptography With Go"

#194

If I had written a book on implementing cryptography in Golang, I assure you that someone else would have reviewed it harshly too. It's simply a difficult subject to get right.

It's not specific to cryptography. There is a hierarchy in all fields: 1. Top researchers come up with algorithms and techniques - The research corpus reviews them 2. Top programmers implements these techniques - The programmers communities review them 3. Top engineers write books to explain these techniques - which everybody else relies on in their tools 1 knows more than 2 which knows more than 3. But each group ne…

How can publishing a book purporting to be the way to do security be considered a first step? A first step would be to get some feed back from experts prior to publishing. This is the real world where this information is critical to our future, not something to be taken lightly. On a human level I have some sympathy for the writer but professionally I think Tptacek's response is completely acceptable and am glad I read it.

Re: Tptacek's Review of "Practical Cryptography With Go"

#195

Earlier quoted context omitted.

Sure, it's irrelevant. It adds some color, but it's unnecessary. But who cares? The complaints are not "this writing could be tighter, it wastes words on unnecessary side notes." They are, "oh my god you're hurting this poor fellow's self esteem with your tone!" It's ironic that these critiques of this review are much dumber than the review's critiques of the book, and implicitly hold a fairly off-the-cuff internet c…

Out of curiosity, how could it have been better?

There isn't a whole lot. I think removing some of the emotional language would help. I prefer my technical articles to be a "just the facts, ma'am" and make an effort to write that way myself. I think it could also have benefitted from some additional explanation of the right way, beyond just pointing out the wrong way. For example, I would love to have seen a brief explanation of why hash functions aren't MACs, and why MAC-then-encrypt is the wrong way to do things. I already have a basic familiarity with that (at least partially from some of your previous comments), but I'm sure your explanation would at the very least help cement the ideas in my mind, and probably teach me something new.

That said, I want to point out that I think your review was excellent and it's the kind of thing I love coming across. It many ways, it reminds me of the heyday of Usenet. It's great content and it doesn't need to be better. To the extent that it can be better, it's because nearly any work can be made better with additional effort.

Re: Tptacek's Review of "Practical Cryptography With Go"

#196

After I finished reading this review, I came to check out the HN comments knowing that the tone would be the subject of the top comments. When did this community become more concerned with tone than correctness? The top of this thread is filled with people saying that the tone is bad, it's unproductive, it's unnecessary, etc. Yet nobody seems concerned about the published book filled with bad information that a lot o…

The tech "community" (if you can even call it that anymore) has jumped a fucking pyramid of sharks.

Being right used to be the ultimate trump over social dynamics, which is what made tech a breath of fresh air to so many. Now that the field has become socially popular, it's been mired in the same vapid talking heads as everywhere else. And the people who actually know things are much quieter, as they generally have better things to do than compete for airtime.

Re: Tptacek's Review of "Practical Cryptography With Go"

#197

Earlier quoted context omitted.

Ironically, you yourself are choosing more 4 than 2 in response to someone's criticism of your criticism.

I made 3 straightforward points in my comment. Do you disagree with any of them? If not, let's just agree to disagree.

I disagree with your condemnation of a behavior while exhibiting said behavior. It shows that you're okay with drama so long as it's you creating it, but you're not okay with a dramatic response to your own drama-creating.

The accusation of elitism on your part is not a new one, I don't think, to you - I found myself levying the same accusation when you decided to single out the CryptoCat project as a distinctly "bad" project, due to the number of issues that came up during the most recent security review, despite the fact that it's one of a very select group of open source projects even undergoing such reviews.

You say things like, "amateur cryptography" when it makes little to no sense. This book wasn't written for free, it was actually professional crypto, even if it had fundamental problems; it's bad crypto, not amateur crypto. When you do things like that, it comes off as elitism, whether or not you're intending it to.

Re: Tptacek's Review of "Practical Cryptography With Go"

#199

I happen to know the author of this. This was a really tough thing for him to read, but he's taking it as constructive criticism. I would add to the people commentating here on HN: tptacek's review is tough; you do not need to lay into the author of this book any more.

How many books has he authored? This is very valuable data, and he stands to make an even better book even if all he does is change diffie hellman to appease tptacek and perhaps other readers.

Re: Tptacek's Review of "Practical Cryptography With Go"

#200

Earlier quoted context omitted.

"I suspect this is often a conflict between the expectations of the children of helicopter parents and my generation." At 49, I see the exact opposite. Members of my generation tended to exhibit more tact and decorum. The urge to dress like a hobo, swear all the time, and flame everyone in sight is a classic overcompensation for years of helicopter parenting which forbade all of these things. "In some cases, it's hon…

In others, it's honesty used as a pretext for acting out. Note I also make this observation. Also note that I am specifically pointing out reactions to criticism. The other changes in decorum have been noted by previous generations since at least the 1800s. Waltzing was once a lascivious corrosive to society's morals. Also: we are likely less than 4 years apart in age. I could do with more decorum, as I've been learn…

I hear you. At the beginning of my career, I always used to be the most offensive person in the room - and I could afford to be, because nobody cared what I thought. Nowadays there are always five people in the room who are more offensive than me, but that won't stop them from complaining if the big bad ogre (me) hurts their feelings. Kids nowadays. ;)
Post reply on HN