5 ms·
> We need to stop saying don’t roll your own and start teaching it with good examples and good explanations. I 100% agree with this statement, in isolation. B
by CiPHPerCoder 4y ago
> We need to stop saying don’t roll your own and start teaching it with good examples and good explanations.
I 100% agree with this statement, in isolation.
But in context, I have to wonder if something in the post sounded like I was telling people not to roll their own? Because that wasn't the take-away.
Either way, https://gotchas.salusa.dev/GettingStarted.html https://gotchas.salusa.dev/GettingStarted.html
> So the way you get to become someone who gives this sage advice is by disobeying it.
Lawyers have a similar thing, from what I've been told.
"Don't go to law school", "Don't become a lawyer", etc. are what many lawyer parents have told their children (some of whom went on to become lawyers themselves).
- melony 4y agoCrypto really isn't the sort of thing you should be doing by yourself, especially implementing crypto algorithms. To correctly implement a crypto algorithm from scratch without existing primitives, you need 1) A basic foundation in discrete mathematics, the type from a CS program and not a web dev bootcamp 2) Strong knowledge of computer architecture 3) Security knowledge of common exploits and vulnerabilities. It is like authoring compilers, most engineers have some knowledge of what's needed. But the few who are lucky enough to get paid to do it full time professionally are not very common. One thing I am thankful for with the hype about cryptocurrencies is that people with understanding of cryptography at the algorithmic are now much more common since the markets are aligned to reward technologies like symbolic execution and probably correct algorithms.
- yccs27 4y agoMan that typo in the last few words cracked me up. "Probably correct algorithm" sounds like "I didn't test the code but it'll probably work fine. Let's deploy it to production!"
- melony 4y ago*provably ;) *algorithmic level I should have proof read it
- mlyle 4y agoAs someone who has "rolled his own crypto" for various reasons, I was just wondering why you're saying this: > 2) Strong knowledge of computer architecture Is it so we can do performant things? Avoid side-channel attacks? Computer architecture isn't focal in my thinking when I'm working on cryptography. Very rarely it becomes important (I could leak information because of ... or boy, that is branch heavy and isn't going to be fast ...)
- GTP 4y agoIt's both, and your example in parentesys actually provides a good example, as brances can both slow you down and provide a side channel (but in crypto I think that in the particular case of branches only the second occurs). If you're looking for an example that is more rooted into computer architecture, you can look at how implementing AES with lookup tables can provide a cache timing side channel.
- mlyle 4y agoWell, then I'd say the knowledge fits more in "3". It's not general purpose architectural knowledge, but rather the wealth of things we've learned from people thinking about side channels.
- GTP 4y agoI think it's hard to pick one between 2 and 3, as after knowing about a possible side channel from 3, you need 2 to prevent it on the specific architecture you'll run your code on.
- mlyle 4y agoI don't know that I agree. Simply speaking, the vast majority of cryptography work has nothing to do with tomfoolery to prevent side channels-- even if we're doing low-level fundamental algorithm stuff, which most of the time cryptographers are not doing. (When's the last time you thought about AES in detail?) The way people stumble is in protocol errors and fundamental errors of composition.
- api 4y ago> Crypto really isn't the sort of thing you should be doing by yourself, Someone did or none of the crypto I use would exist.
- pessimizer 4y agoAre you sure that the crypto you use was done by somebody who wasn't an expert in crypto, by themselves?
- api 4y agoOf course it was done by an expert, but how did this person become an expert?
- pixl97 4y agoLawyers at least are going to a school to be professionally trained... If you're going to roll your own crypto maybe make sure you're professionally trained.
- Zenst 4y agoWould it not be better to have some accredited auditing sevice that can verify and certify crypto code? After all, the whole infosec feild moves fast and what was 100% professinal at the time of being trained with the then known aspects does not mean that they would hold true today. Heck I'm certified to recogise drugs and bombs, yet I'd not have any idea upon many modern drugs or explosives, so in some eye's I qualify as a professional and in my eye's I'm far from it and garantee many who have no such acreditation would be far better than I.
- api 4y agoOkay, then we need to tell people where to get this professional training. What should one do before one rolls their own crypto? But nobody does that. Nobody says "don't roll your own crypto until you learn these things and pass these tests." They just say don't, and the people saying don't are often the ones who are. So it's ignored, and with no good guidance people write crappy crypto.
- CiPHPerCoder 4y ago> Okay, then we need to tell people where to get this professional training. I posted a link to a Getting Started guide in my comment above. Once you've exhausted those resources, your best bet is to join a cryptography team at a tech company to round off your education with some real-world experience. For example, https://www.amazon.jobs/en/search?business_category[]=amazon-web-services&base_query=crypto%20tools https://www.amazon.jobs/en/search?business_category[]=amazon...