James Muir <[email protected]> writes: >But Peter, where could someone find one of these "security libraries" you >speak of? ;-)
I realise that sounds like self-promotion, but it was written from the basis if > 15 years maintaining a security library and having seen... I was going to say every mistake in the book, but I'm sure there are plenty of mistakes left that haven't been used yet. The result is what I called second-derivative snake-oil crypto in "Lessons Learned in Implementing and Deploying Crypto Software" (http://www.usenix.org/publications/library/proceedings/sec02/gutmann.html), stuff that's no longer obviously snake oil due to use of homebrew encryption algorithms but nonobvious snake oil due to misuse of crypto primitives by people who don't understand them, when all they have to do is use the higher- level constructs provided by many/most security libraries. Peter. _______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
