James Muir <[email protected]> writes:

>But Peter, where could someone find one of these "security libraries" you
>speak of? ;-)

I realise that sounds like self-promotion, but it was written from the basis
if > 15 years maintaining a security library and having seen... I was going to
say every mistake in the book, but I'm sure there are plenty of mistakes left
that haven't been used yet.  The result is what I called second-derivative
snake-oil crypto in "Lessons Learned in Implementing and Deploying Crypto
Software" 
(http://www.usenix.org/publications/library/proceedings/sec02/gutmann.html),
stuff that's no longer obviously snake oil due to use of homebrew encryption
algorithms but nonobvious snake oil due to misuse of crypto primitives by
people who don't understand them, when all they have to do is use the higher-
level constructs provided by many/most security libraries.

Peter.
_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography

Reply via email to