Hacker News new | past | comments | ask | show | jobs | submit login

Exactly the wrong perspective; most crypto vulnerabilities stem from the "glue code".



People hear "don't roll your own crypto", and think that it means "don't invent your own encryption algorithm". Really it should be reprhased, "don't ever touch crypto directly".


I understand, I Must Not Write Crypto Code™. However I choose to write whatever I want anyway, crypto experts must not be the only ones writing crypto flaws, so can i.


I don't care what you write, but if you go into it thinking that the dangerous stuff is in the primitives like the AES core, and if you just stick to the glue you'll be safe, you're gonna have a bad time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: