Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month at the Massachusetts Institute of Technology, in Building E51.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Good and Bad Crypto



> From: discuss-bounces+blu=nedharvey.com at blu.org [mailto:discuss-
> bounces+blu=nedharvey.com at blu.org] On Behalf Of Derek Martin
> 
> Anything involving security or encryption is rarely simply anything.

Point?


> Hogwash.  The difference is interested, qualified parties can't
> inspect the implementation to see if, say, using a particular key
> won't make the implementation upload logs of all your transactions to
> a black hat site, or download kiddie porn to your hardrive, etc..
> If you can't inspect it, you can't trust it.  Period.

In invite you to join us in the real world.


> > Nobody rolls his own crypto algorithm.  And I mean nobody.
> >
> > Everybody, and I mean everybody, uses a standard library implementation
> of an open standard.
> 
> This is also utter nonsense.

Nice link to 1996.  Ever since strong crypto became freely available and widely publicized, scrutinized, and packaged up into convenient libraries, the only people who write new experimental block ciphers are those people who are competing to become the next AES, SHA, etc.

In practice, all modern cryptography is using standard libraries, and if you're insane enough to deviate from the path, you deserve what you get.  Nobody does it.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org