3 ms·
This is my experience when studying material on cryptography. You need a cryptography library implementation for language X: - Crypto implementation for langu
by max_ 2y ago
This is my experience when studying material on cryptography.
You need a cryptography library implementation for language X:
- Crypto implementation for language X doesn't exist
- You try to read papers defining the crypto scheme.And they use variables like K and phrases like "oh this is from the group G"
- You spend weeks trying to understand what G and K are.
- You finally implement the crypto algorithm in language X
Academic cryptographers that write papers and no code:
Only "academic cryptographers" have the right to implement crypto schemes.
It's very frustrating working on cryptography schemes in obscure languages and their are no ready libraries.
And reading original papers often feels like there is alot of proactive gate keeping.
- tcoff91 2y agoMost of the time, obscure language can call out to C. Therefore you should almost certainly just use FFI and leverage a C implementation of whatever crypto algorithm you want to leverage.
- max_ 2y agoWell, that's a possible solution. But often FFIs pollute the reason one chooses to use obscure languages.
- bluGill 2y agoTrue, but encryption should generally be an exception to that rule. Not that C is good for writing encryption, but because there are so many weird issues with encryption which can result in an implementation that passes all the test to still be severally broken. At least the C version has had a lot of experts looking at it and preventing those issues.
- tcoff91 2y agoYou shouldn't be rolling your own crypto primitives. You can completely implement the algorithm 100% 'correct' according to the research paper but introduce a side channel that could cause key extraction by an attacker. For instance, if it doesn't always take the exact same amount of time to process something, a timing attack can be used to figure out what the private key is. Always use the battle tested implementation. Power analysis, timing attacks, acoustic cryptanalysis, etc... there's many forms of side channel attacks that can be used to defeat a theoretically sound cryptosystem.
- SilasX 2y agoRelated: in tptacek’s Cryptopals/Matasano security challenge, there are two kinds of problems: A) Implement this off-the-shelf cryptosystem based on the public documentation about it. B) Given this cryptosystem and these hints, find and exploit a vulnerability. Surprisingly, I found the type A problems harder — because the documentation was always missing some critical knowledge you were just supposed to know.