8 ms·
Crypto 101 – Introductory course on cryptography
- langitbiru 8y agoThere is also a cryptography course from Udacity: https://www.udacity.com/course/applied-cryptography--cs387 https://www.udacity.com/course/applied-cryptography--cs387
- harias 8y agoCryptography 1 by Stanford on Coursera is really good too : https://www.coursera.org/learn/crypto https://www.coursera.org/learn/crypto
- codetrotter 8y agoIn the “secure computation” part, do you learn how to do such computation or is it just another explanation of what it is? I know the “what” of this but not the “how”. If this teaches me what I need in order to go and actually implement it myself then I am interested.
- hardwaresofton 8y agoA resource I found really helpful was a fantastic classroom-setting lecture series Introduction to Cryptography by Christof Paar[0] . [0]: https://www.youtube.com/watch?v=2aHkqB2-46k https://www.youtube.com/watch?v=2aHkqB2-46k
- charlysl 8y agoSeconded, I am working my way through this course and its fantastic, specially if you also do all the homework problems.
- qwerty456127 8y agoCool, thanks! BTW why is EPUB mentioned but not available?
- lvh 8y ago(I'm the author.) Because it's not a priority for me and I never got the org -> epub generation flow working correctly. In particular, the book has a lot of illustrations, and getting illustrations right across a ton of ebook readers is quite complicated. To wit: they all support different formats and to get it more or less compatible you have to guess what the approx DPI is for most of those devices and then rasterize the vector imagery. If someone gets it to work I'd be much obliged, it just hasn't been a priority for me :)
- qwerty456127 8y agoI see. > what the approx DPI is for most of those devices and then rasterize the vector imagery As far as I know you can use SVG illustrations in EPUB. Alternatively you probably could rasterize to a redundant resolution and rely on the viewer app to downscale the pictures to fit the page width.
- lvh 8y agoYou can, but at least a few years ago most cheap readers would horribly mess that up (usually not render it at all). And those that didn’t were typically nice enough that they could just render the PDF correctly ;)
- wbkang 8y agoI read the book, it is well written, accessible and pretty accurate. I think it's worth a skim even just to learn more about something you vaguely know but you can't explain in your own words.
- lvh 8y agoI'm glad you feel that way, because I'm honestly embarrassed by how shoddy my old writing is. (I'm the author.)
- leroy_masochist 8y ago+1 for the fact that the "get book" button on linked site just downloads the pdf.
- weinzierl 8y agoThanks, for the comment. I wouldn't have bothered with this otherwise. Normally a "Download our PDF|Whitepaper|Whatever" is a 100% sure way to make me close a site immediately nowadays - and this is what I did. Just stumbled upon your comment because the tab was still open and it was the first comment. VirusTotal seems to be cool with the file too, so that's how it should be. https://www.virustotal.com/#/file/fe42077288cfaa6d1d1b83c088751e9224323cdec2a0c1904f0571e28a1f9cd4/detection https://www.virustotal.com/#/file/fe42077288cfaa6d1d1b83c088...
- leroy_masochist 8y ago> Normally a "Download our PDF|Whitepaper|Whatever" is a 100% sure way to make me close a site immediately nowadays I don't know what I was doing clicking on it to begin with, usually a surefire way to get a fresh copy of MacKeeper or something
- lvh 8y agoYou can get the org mode plaintext source here: https://github.com/crypto101/book https://github.com/crypto101/book. It doesn't read as well as the PDF because there's a ton of illustrations and _something_ has to render them.
- black-tea 8y agoI find it amusing that you wrote the book using org-mode but the README using ResT.
- HackAllThings 8y agoStarted reading it, pretty good so far! Only thing, why did you choose to introduce block cipher modes in the stream cipher chapter? This makes little sense to me.
- aaachilless 8y agoChapter 6 is block ciphers, Chapter 7 is stream ciphers. Also, the first lines in chapter 7: Let’s try to build a stream cipher using the tools we already have. Since we already have block ciphers, we could simply divide an incoming stream into different blocks, and encrypt each block...
- lvh 8y agoBecause the book tries to produce a narrative where new features are introduced out of obvious necessity: in this case, encrypting more than a block. And you can do that with modes of operations or "native" stream ciphers. Essentially I'm handwaving and pretending that e.g. AESCTR is just a stream cipher :-)
- throwawaymath 8y agoIt actually makes a lot of sense for practical purposes. This probably looks strange to you because most introductory cryptography texts strictly segregate stream and block ciphers. The standard pedagogical style bifurcates modern symmetric encryption into one of these two categories and talks about things like synchronization, on-the-fly encryption, speed, error correction, etc. between the two. In point of fact, there isn't as significant a difference between the two in active research and industry. Many (most?) stream ciphers actually use blocks internally. For example, Salsa (and its spiritual successor, ChaCha) both use blocks and rounds. From one legitimate perspective, a block cipher mode enabling streaming encryption is a generalization of a stream cipher. When you develop a stream cipher without a block system internally[1], you're trying to remove the versatility of block cipher modes in exchange for (hopefully significant) improvements in speed and efficiency. This is very difficult to do while maintaining security. At the end of the day there are only so many ways to do confusion and diffusion. _______________________________ 1. For example see Sosemanuk, which internally uses a linear feedback shift register and finite state machine.
- lvh 8y agoHi! I'm the author. Happy to answer questions.
- CiPHPerCoder 8y agoHi lvh, Do you intend to complete this book at some indeterminate point in the future? Is there anything that any of us can do to help make it happen?
- lvh 8y agoI'm not sure what "complete" would entail :) For example: would a description of Noise be in scope? I think so but I'm not sure. People come up with new cool stuff that's useful to median developers on the regular (say, NMR) that feels like it ought to be added/updated. So I think it's forever a WIP and that's OK since I'm not really printing the book?
- smkdtr 8y agoThank you for writing this book! I recently used this book to brush up on crypto fundamentals for some interviews and found it really valuable. I was even able to implement a padding oracle attack after only knowing it in theory for a very long time. I was also wondering if you had any plans to complete. Right now, there are 36 TODO's in the book. Not all of them need further explanation and can be left as an exercise but some of them might be useful to dig into. Regardless, it is still awesome!
- lvh 8y agoI definitely want to work on it more but I think completion goals are going to be at a chapter level maybe -- there'll always be stuff to add :)
- pvg 8y agowould a description of Noise be in scope? Yessss! Utterly selfishly: things like 'Noise Protocol Matrix' or 'Nonce misuse resistance 101' are actually closer to your target than XOR diagrams that people can already find on wikipedia.
- raister 8y agosuperficial stuff
- lvh 8y agoWhat would you have preferred to see that wouldn't make it "superficial"?
- raister 8y agoAES explanation before DES? Why? It doesn't make any sense.
- lvh 8y ago... because the only way to introduce ciphers is, what, chronologically? Why? And why does that make it superficial?
- raister 8y agoAAMOF, I've never seen a more shallow explanation of AES... and I find it rather superficial for this reason. Man, that's nice you have written a book, now plant a tree, have a baby, and relax... take a constructive review on your work. Use it to improve that version.
- CiPHPerCoder 8y ago> Man, that's nice you have written a book, now plant a tree, have a baby, and relax... take a constructive review on your work. Use it to improve that version. Your feedback isn't really actionable. How is the author supposed to use anything about your feedback to "improve that version"?
- deadmetheny 8y agoYou've said literally nothing that could be considered constructive.
- 8y ago
- komali2 8y agoOh interesting. I recently got "Applied Cryptography" in one of the nostarchpress sales. I expected it to be turbo technical and way outside my league but popped it open on a whim one day. So far it's incredibly accessible, does anyone have thoughts on that versus this course? Worth taking the course after I finish Applied cryptography?
- lvh 8y agoDo you mean "Serious Cryptography"? Applied Cryptography isn't a No Starch Press book.
- komali2 8y agoNo, I do mean Applied Cryptography. I may have picked it up in a humble bundle sale in hindsight.
- lvh 8y agoGotcha. Serious Cryptography is good. Applied Cryptography is... not. Except insofar Latacora making stickers that make fun of it and people printing t-shirts to benefit charities is good of course :-)
- SAI_Peregrinus 8y agoIt's also good for historical interest. It was a great book for its time. Now it's horribly outdated, even Schneier recommends against using it for anything other than learning about the state of academic cryptography in the '90s. Which is important, but not relevant to modern cryptography.
- blattimwind 8y agoIncidentally, Applied Cryptography is often critiqued for making crypto seemingly easy and incredibly accessible, which led to some people implementing very nice fails. For practical purposes the later Cryptography Engineering book is probably a better choice.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- dang 8y agoFrom 2016: https://news.ycombinator.com/item?id=13089489 https://news.ycombinator.com/item?id=13089489
- arc_of_descent 8y agoThanks for this. I just finished the XOR stuff and can't wait to read more!
- arthur5005 8y agoI skimmed through it this morning and was genuinely surprised by its accessibility. The concepts are as I remember from my cryptography course in college, and is a great refresher! Thank you!
- raspo 8y agoI just watched the talk on that page, it was fantastic! Especially for dump developers like myself who never studied actual CS or math. Thanks for sharing.
- 384028345 8y agoFYI: I just put the PDF on my Kindle Paperwhite and it actually looks like a regular ebook in terms of font size and readability so far.
- dingoegret 8y agoDamn that PDF is a good read. Visuals visuals visuals. Good stuff
- person_of_color 8y agoHow does this compare to Crypto 1 on Coursera?