4 ms·
I read the blog post earlier and this one line really resonated with me: we don't assess the structure of bridges by asking "has it collapsed yet?" Security is
by Oculus 13y ago
I read the blog post earlier and this one line really resonated with me: we don't assess the structure of bridges by asking "has it collapsed yet?"
Security is one of those notoriously hard fields to get right for precisely this reason: you don't know you're doing a bad job until it's too late.
- BrandonM 13y agoI like that. I think by that measure, though, OpenSSL is failing badly. It's like an old rusted-metal and rotten-wood bridge that should have a sign saying, "No vehicles over 2 tons," but instead it's carrying highway traffic. I'm starting to get frustrated by the security experts basically chasing everyone away from cryptography. Am I the only one getting tired of the experts (many with misaligned incentives) telling us, "This stuff is really hard... Just trust us"?
- 001spartan 13y agoThe fact remains that crypto _is_ very hard. I don't see why telling people that equates to "chasing people away" from cryptography. It would be even more dangerous to not mention that fact when people try to roll their own encryption systems. It's just not something that can be safely done by a hobbyist/amateur, at least not for critical applications.
- BrandonM 13y agoIn many other areas of CS (e.g., gaming, language development, DB design), the experts are simply more willing to discuss or enumerate the requirements of the problems they are solving. They make an effort to educate those who are interested in learning. In security, you have a cabal of self-appointed experts who write inscrutable code and chastise you if you try to improve on it. What does that accomplish other than chasing people away? These security experts make their livelihoods based on their credentials; they have every incentive to keep others out. At what point do we stop giving them the benefit of the doubt and start educating ourselves? Trust can only go so far.
- 001spartan 13y agoDisclaimer: I'm an infosec student/enthusiast, so I may have a different perspective. Also, it's late; it's entirely possible that this is sleep deprivation talking. I think it's more a case of the subject being so important that it's not really something that you can take shortcuts with. When it's something so critical to daily life as the internet is becoming, it's imperative that all code made for security purposes is carefully considered, and architected to avoid the tiniest bugs. Hobbyists or amateurs (myself included) are not necessarily qualified to judge what might constitute a critical bug, and that is one of the reasons the barrier to entry in the field is so much higher.
- BrandonM 13y ago> it's imperative that all code made for security purposes is carefully considered, and architected to avoid the tiniest bugs. I agree wholeheartedly, but all you have to do is take a look at these security libraries' code, processes, and recent bugs to realize that the experts are failing at this. Their math and theory may be flawless, but their code is shit. I think cryptography could benefit greatly from an influx of software engineering. We should be using modern testing and code review practices to bring some measure of reliability and architectural clarity to cryptographic work. The attitude toward programmers who aren't experts (yet!) doesn't exactly encourage this.
- 001spartan 13y agoThat is very true. However, the number of people who are both good software engineers and good cryptographers is very low. Personally, I can't say that I've seen experts being hostile towards those willing to learn the concepts and best practices for cryptography, though. The hostility is usually reserved for those who try to roll their own crypto with ill considered design, no matter how nice their code is (Telegram, etc). But it's possible that I could be entirely out of touch with that.
- cperciva 13y agoThe fact remains that crypto _is_ very hard. I don't think it is any harder, actually. It's just that the stakes are much higher.
- 001spartan 13y agoI'll grant you that. Crypto is just one aspect of the security field that doesn't seem very intuitive to me, but it's probably just me.
- erichurkman 13y agoBased on how many security issues the internet has seen from developers that try to roll their own crypto: it's not just you.
- willvarfar 13y agoYou say its no harder, but the risks are higher. A lot of crypto is unintuitive. And the goal-posts keep moving. You have to keep well-read and very objective. You can say this about mainstream programming, but its a bit of a stretch. There is plenty of mainstream programming using the equiv to bubble sorts and nobody should care. You can get away with being a bad programmer. Because the risks are higher, and you can't get away with being mediocre, is why crypto is hard. PS: not a tarsnap user, but love your work and your thoughtful posts :)
- cperciva 13y agoPeople using bad algorithms is exactly the sort of thing I was thinking of. People write horribly broken code in every context; but instead of a bug making software slower than it should be, when an "equally dumb" bug happens in crypto code it probably reveals your keys.
- wglb 13y agoWell, you do understand how to write proveable programs. Most programmers do not.
- deleted 13y ago[deleted]
- jacques_chester 13y ago> I read the blog post earlier and this one line really resonated with me: we don't assess the structure of bridges by asking "has it collapsed yet?" Actually, there's a school of thought that this is exactly how bridges are assessed. Henry Petroski's To Engineer is Human argues that structural engineers never have have successful structures. They only have the current absence of failure. I reviewed it here: http://chester.id.au/2013/07/07/review-to-engineer-is-human-the-role-of-failure-in-successful-design/ http://chester.id.au/2013/07/07/review-to-engineer-is-human-...