Live data from Hacker News

Tptacek's Review of "Practical Cryptography With Go"

gist.githubusercontent.com

21–30 of 255 posts

Re: Tptacek's Review of "Practical Cryptography With Go"

#22
post #2

This is a good illustration of how, 1) crypto is hard 2) real-world cryptosystem design & implementation is hard and 3) teaching the aforementioned is hard. I read Schneier's & Ferguson's Practical Cryptography years ago, the only thing I remember about it is the "don't try this at home" message.

"Don't try this at home" is good practical advice for building real systems that have real users. It's terrible pedagogy, though. You have to learn somehow, and trying it at home is actually how you do that.

Re: Tptacek's Review of "Practical Cryptography With Go"

#23
post #9

For those of you who don't know what the acronyms stand for, I've compiled a list, in order by their appearance: AES - Advanced Encryption Standard CBC - Cipher Block Chaining PKCS - Public Key Cryptography Standards SHA - Secure Hashing Algorithm MAC - Message Authentication Code PBKDF - Password-Based Key Derivation Function NIST - National Institute of Standards and Technology FIPS - Federal Information Processing…

PS3 is correct. That was a particularly amusing episode, well worth looking up the full story.

Re: Tptacek's Review of "Practical Cryptography With Go"

#25
post #19

From tptacek's comment, it sounds like the author of the book may just be an inexperienced practitioner of cryptography who's only crime is to be too eager to spread what they've learned. Someone who picked up the basics from a few Wikipedia articles here, a few papers there, a couple open source projects here and there... they're smart, so they're not completely clueless about the field, but they just don't have the…

At least I got an impression that Tptacek's most points are easily accountable so lets wait for Practical Cryptography With Go, 2nd Ed. :)

Re: Tptacek's Review of "Practical Cryptography With Go"

#27
post #9

For those of you who don't know what the acronyms stand for, I've compiled a list, in order by their appearance: AES - Advanced Encryption Standard CBC - Cipher Block Chaining PKCS - Public Key Cryptography Standards SHA - Secure Hashing Algorithm MAC - Message Authentication Code PBKDF - Password-Based Key Derivation Function NIST - National Institute of Standards and Technology FIPS - Federal Information Processing…

PS3 is correct. That was a particularly amusing episode, well worth looking up the full story.

http://vimeo.com/18274128#t=28m28s

Re: Tptacek's Review of "Practical Cryptography With Go"

#28
can someone explain this?

    * This book, I am not making this up, contains the string: "“We can use ASN.1 to make the format easier to parse".

Last time I had something to do with ASN.1 was years ago but it seemed to work well, libraries were full featured and cross-language interop was ok. What am I missing that makes ASN.1 bad ?

Or is the critique to an attempt to write a custom ASN.1 serializer/parser?

Re: Tptacek's Review of "Practical Cryptography With Go"

#30
post #19

From tptacek's comment, it sounds like the author of the book may just be an inexperienced practitioner of cryptography who's only crime is to be too eager to spread what they've learned. Someone who picked up the basics from a few Wikipedia articles here, a few papers there, a couple open source projects here and there... they're smart, so they're not completely clueless about the field, but they just don't have the…

An "inexperienced practitioner of cryptography" should not be writing a book about cryptography. It's great that such a person is learning, but you shouldn't be trying to pass on such information at that stage.

(I don't know the author either)

Post reply on HN