3 ms·
> - You shouldn't try to invent your own cryptographic primitives. > - You shouldn't try to design your own equivalent to (say) SSL. > - You shouldn't try to
by janeroe 5y ago
> - You shouldn't try to invent your own cryptographic primitives.
> - You shouldn't try to design your own equivalent to (say) SSL.
> - You shouldn't try to implement something like SSL, or parse ASN.1, yourself.
Why not? You should do all those things, how else can one get a deeper insight into how things work. It's just that you probably don't want to use that in production environment unless you really know what you're doing.
- bostik 5y agoYou make a good point, but I feel it's getting downvoted thanks to the implied tone. > [...] get a deeper insight into how things work. It's just that you probably don't want to use that in production [...] That is the gist of it. If you are really into applied cryptography, then rolling your own crypto - and I can't stress this enough - for PURELY ACADEMIC purposes is fine. As long as you are honest with yourself, writing some applied crypto code is a good way to learn some of the horrible ways things can go wrong. Know deep in your heart that no matter how well you thought you did, the code you wrote is broken. Badly. The "oh... oh shit..." realisation when looking back at the code will be enlightening. Just please, for the love of all that is good, do not publish the code you wrote. Otherwise, thanks to the law of large numbers, someone, somewhere will grab your code, embed it in their production systems and the next thing you know, a toy library you wrote is now responsible for yet another IoT disaster.
- adgjlsfhk1 5y agoOr, here me out, roll your own crypto, and put it on a webservers that GPT-2 generated messages back and forth. That should give an intern at the NSA/KGB a really annoying summer.
- tialaramex 5y ago> how else can one get a deeper insight into how things work Learn from other people's mistakes. You cannot possibly afford to make all those mistakes yourself.