3 ms·
Your post hit a lot of notes I agree with. Programming dogma doesn't make a lick of sense sometimes. I wonder if the "don't implement cryptography yourself" rul
by mykull 9y ago
Your post hit a lot of notes I agree with. Programming dogma doesn't make a lick of sense sometimes. I wonder if the "don't implement cryptography yourself" rule is disingenuous, and really about not necessitating more work from our governmental APTs to get peepholes into everything.
I'm also amazed at how often people cry premature optimization when there's potential to reduce hardware cost by orders of magnitude by not writing slow, memory hungry junk by default.
- Nomentatus 9y agoI feel you. While there's plenty of history (hundreds of years) to indicate you shouldn't rely on rolling your own (though Jefferson did, and did a helluvagood job.) It's crazy easy to fool oneself about how great one's own crypto is. However, what you can do is roll your own and then encrypt your data once again - after that initial encryption - with excellent standard methods. This can allow decryption in parallel in some circumstances - if you want the best speed - by encrypting a one-time-pad with the roll-your-own and sending that in advance (and decrypting that pad in advance, so you just have to xor it into the mix later.) When encrypting fer real, first use the one time pad on the data and then encrypt it with regular methods.