3 ms·
I'm interested in learning more about this- do you have any recommended resources for getting started?
by technics256 5y ago
I'm interested in learning more about this- do you have any recommended resources for getting started?
- marcan_42 5y agoI don't have any specific pointers handy, but it might be a good idea to look through historical security vulnerabilities in widely-used protocols like TLS (and x.509 certificates). The cryptography/security community has slowly understood over the past couple of decades that complexity is the enemy of security, and it is much better to build stupid simple systems that you can validate (and ideally prove are secure) over complex systems which are almost certain to contain exploitable corner cases. This also ties in with general security hygiene and understanding; you need to know what is trusted, what is untrusted, and how to make them interact. Ideally you don't validate untrusted data; instead you build your system so that is not necessary. Every validation that needs to be performed is one more place where something can go wrong. If you need to validate a signature, you go and validate it; you don't ask the user to do it and then validate that they really did it properly and the validation happened. That's what happened here, as far as I can tell. The extra, avoidable validation went wrong.
- balls187 5y ago> it is much better to build stupid simple systems ... over complex systems which are almost certain to contain exploitable corner cases. This popped into my mind when reading your comment. https://www.youtube.com/watch?v=eU2Or5rCN_Y https://www.youtube.com/watch?v=eU2Or5rCN_Y