-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/384/oh-the-bad-crypto-youll-see-an-open-letter/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
You're Not Special (98%):
Separate your marketing department's claims about your product's external view from the internal design. Nearly all problems boil down to ones already solved by existing protocols and libraries. Encrypting a file? GPG. Sending anything over the wire? TLS/SSL. Your special sauce is in how you glue all these things together to make some product. Don't reimplement these, and still get review of how you've glued them together.
You Are Special (2%):
You are Voltage and you were founded by Dan Boneh. Or your business is cryptanalyzing products in concert with Adi Shamir. Note the most important part here -- if you're special, you are willing to plunk down $400/hour for a full-time cryptographer for at least 6 months.
'you are going to use TLS, with a peer-reviewed library, meaning, the same one everyone else uses.'
That's most definitely a key point to get across which in most cases gets brushed under the carpet and as Nate posts above, there's only a small fraction of people who shouldn't be doing this, the reality however is unsurprisingly common.
actively tend to the most popular implementations (OpenSSL, GPG), because those are the ones that receive scrutiny.