Re: ODT Today
Daniel Beer <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.dunedin.general |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Apr 16, 2014 at 10:29:01AM +1200, Paul Campbell wrote: > one of the points made at foo is that we're continually told that mere mortals > shouldn't do crypto - and that's meant that not enough people have looked > critically and a core piece of infrastructure. > > Good programmers may not understand the core math involved, but we can still > look at the C and find the same sorts of bugs we make when we write it Yep, and a lot of good implementations of good algorithms aren't as complicated as the OpenSSL source would lead you to believe. The reference implementations of Poly1305 and Curve25519 in NaCl are interesting reading: a total of 360 lines of portable and reasonably fast C. No external dependencies, no memory allocation, and no timing leaks. Cheers, Daniel -- Daniel Beer <[email protected]> www.dlbeer.co.nz IRC: inittab (Freenode) PGP key: 2048D/160A553B _______________________________________________ DunLUG mailing list [email protected] http://lists.ethernal.org/listinfo/dunlug DunLUG Wiki - http://dunlug.kallisti.net.nz/