Tptacek vs. Filosottile on rolling own crypto
twitter.com
twitter.com
Where I've disagreed with Tptacek in the past is on cipher fixation. Making everything in the world use AES and having all hardware offloading only accelerate AES is something I would expect from the military or lazy hardware developers. Rijndael (AES) was not even supposed to win the competition, but NIST made it win. The article on the competition has had some revisions. Either way, I do not like being limited to one or two ciphers. There should be many and we should rank them in strength. There should be annual competitions to break each of them. When one is "broken", it should be deprecated via a scoring system, but not made obsolete, because broken usually has varying degrees of real world feasibility. Each industry should then decide which ciphers are appropriate for their own risk tolerance.
When it's only me talking to me, I "roll my own" and layer it on top of standard encryption libraries. Nobody can complain about that unless their goal was to decrypt my communications to me. It's not really "rolling my own" so to speak, I just make subtle math changes to the standard libraries. This goes back to a lesson I learned some time ago when messing up a friends Rubix Cube. The more subtle changes I made, the longer it took him to solve it. That is just my personal preference for my own things and only affects me.