3 ms·
dumb question: but why is it so hard to create very-secure crypto libraries? i recall NASA's code used during the Apollo missions had like an ungodly low error
by colorincorrect 7y ago
dumb question: but why is it so hard to create very-secure crypto libraries? i recall NASA's code used during the Apollo missions had like an ungodly low error rate, so surely it's feasible in practice? admittedly, comparing anything to NASA standards is a very high bar to set, but considering the stakes involved with cryptography, you'd imagine a similar scrutiny?
- emmelaich 7y agoApollo computers had input that was trusted, and predictable (within ranges). It only had one job to do. Albeit a big job. Crypto libs (or any libs) typically can be used in a vast number of ways with completely untrustworthy input.
- seanhunter 7y agoI would add that in the beginning, a number of crypto libraries (I'm looking at you in particular, openSSL) made a design decision to support a huge variety of algorithms, options, modes of operation etc. This makes it very difficult to test the full functional surface of the software and means you just have to write a very large amount of code. Some of the modern libraries take a different approach where they deliberately limit the functionality to a few select things that can be implemented easily (thinking nacl, libsodium, boringSSL etc here) and which guide the user towards sensible defaults that work rather than having huge numbers of levers to tweak, only some of which arrive at a secure and supported solution.
- sixplusone 7y agoThe government has very deep pockets. And working for the biggest project of the century probably attracted decent talent, whereas there's no glory in writing supporting libs - you either did it right and nobody notices, or you messed up and get blame.