Problems with Proposed IP Cryptography [1995]
cs.ucdavis.edu
cs.ucdavis.edu
I found this while researching one of the recent OpenBSD crypto fixes, and it is fan-freaking-tastic. This is Phil Rogaway, a world-famous cryptographer, addressing weaknesses in early proposals for IPSEC. There is no better way to learn about this stuff than to watch an expert beat the crap out of an early, flawed system.
More importantly, it's incredibly readable! It could just as well be titled "Nine Lessons For Designing Cryptographic Protocols". And it's written for IETF-types, protocol designers, not cryptographers.
I think this is a gem, I'm glad I stumbled across it, and I hope you get some value out of it.
Low point: Saying MD5 is too slow. We have the opposite problem today.
Timing attacks don't exploit properties of hash algorithms; in fact, they would prefer compute to be slower (and networks to be faster).