3 ms·
I agree in general, but you are painting with too broad strokes here: > No part of cryptography has anything to do with the code. There have been successful a
by maggit 13y ago
I agree in general, but you are painting with too broad strokes here:
> No part of cryptography has anything to do with the code.
There have been successful attacks against cryptography based on attacking the implementation. For example if two code paths take different time to execute, it is possible that this leaks information.
This is another reason why you should use a well honed library implementation of cryptography, for example OpenSSL.
This does of course not imply that the crypto–the maths of it–is broken. One just needs to be aware that it is not, in fact, sufficient to implement the maths correctly.
- RyanZAG 13y agoYou're correct, and I think that means I'm painting my strokes not broad enough. After you get your math peer reviewed, you then need to get your implementation of the math peer reviewed as well - likely by a low-level hardware engineer and not just some web developers. Generally, however, nearly all failures of security come from misunderstanding the math when creating the implementation. So I'd say that at least ensuring anybody writing crypto has a completely understanding of the crypto math before touching the code is a very good first step in getting somewhere.