3 ms·
I got the same vibe from the chorus of "never roll your own crypto" rhetoric I heard on the Internet -- that I shouldn't even bother looking into OpenSSL's code
by gpcz 12y ago
I got the same vibe from the chorus of "never roll your own crypto" rhetoric I heard on the Internet -- that I shouldn't even bother looking into OpenSSL's code unless I went to the Shaolin Temple of Crypto and trained under Master Schneier for 10 years. Just because the intent of the message was one thing doesn't mean that it won't be interpreted in a completely different way by the intended audience.
- dublinben 12y agoLooking at OpenSSL source code and fixing a bug are pretty much the exact opposite of "rolling your own crypto."
- gpcz 12y agoThe impression I got from "don't roll your own crypto" (especially after the Debian key bug thing) was that crypto code was so nuanced and complicated that even if you thought something was a bug, you were likely to be horribly wrong for really complex reasons outside the realm of understanding of anyone who wasn't an expert, and everyone would laugh at you for even bringing it up. After an entire webpage was created to ridicule the Debian developers for how stupid they were when they changed something in OpenSSL's code in their distro's version (complete with references to Dilbert strips about faulty random number generators), I just assumed that I shouldn't even bother trying to look at OpenSSL's code (and especially not try to send patches or ask questions on their mailing list) unless I was willing to make a lifestyle out of it, lest I get ridiculed in the same way (but probably not at Debian's magnitude). I wasn't willing to make a lifestyle out of it.
- dasil003 12y agoObviously a lot of security people and cryptographers develop a holier-than-thou attitude, no doubt from spending their lives scrutinizing things that people continuously get wrong and for which failure is catastrophic. That attitude, off-putting though it may be, shouldn't cause us to read too much into what they say.