BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Good and Bad Crypto
- Subject: [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Tue, 22 Apr 2014 17:58:01 +0000
- In-reply-to: <20140422153609.GL3247@dragontoe.org>
- References: <14b5446b65314ece8402914040d7efb6@CO2PR04MB684.namprd04.prod.outlook.com> <5355DA7B.4070600@gmail.com> <f134eeeef944486ca75cd35da6f930e7@CO2PR04MB684.namprd04.prod.outlook.com> <20140422153609.GL3247@dragontoe.org>
> From: discuss-bounces+blu=nedharvey.com at blu.org [mailto:discuss- > bounces+blu=nedharvey.com at blu.org] On Behalf Of Derek Martin > > Anything involving security or encryption is rarely simply anything. Point? > Hogwash. The difference is interested, qualified parties can't > inspect the implementation to see if, say, using a particular key > won't make the implementation upload logs of all your transactions to > a black hat site, or download kiddie porn to your hardrive, etc.. > If you can't inspect it, you can't trust it. Period. In invite you to join us in the real world. > > Nobody rolls his own crypto algorithm. And I mean nobody. > > > > Everybody, and I mean everybody, uses a standard library implementation > of an open standard. > > This is also utter nonsense. Nice link to 1996. Ever since strong crypto became freely available and widely publicized, scrutinized, and packaged up into convenient libraries, the only people who write new experimental block ciphers are those people who are competing to become the next AES, SHA, etc. In practice, all modern cryptography is using standard libraries, and if you're insane enough to deviate from the path, you deserve what you get. Nobody does it.
- References:
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] Good and Bad Crypto
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Good and Bad Crypto
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] Good and Bad Crypto
- Prev by Date: [Discuss] BTSync
- Next by Date: [Discuss] Good and Bad Crypto
- Previous by thread: [Discuss] Good and Bad Crypto
- Next by thread: [Discuss] Good and Bad Crypto
- Index(es):