Practical Cryptography for Developers
cryptobook.nakov.com
cryptobook.nakov.com
The MAC/HASH stuff seems a bit fuzzy, too; for instance, part of the idea behind SHA-3 is not needing the HMAC construction anymore. Also, a bit strange to have MACs and KDFs in the same section. Are they closely related?
The bcrypt vs. scrypt vs. Argon2 stuff, also, is pretty unclear.
I think the randomness coverage is actually pretty bad. For instance, it walks programmers through building their own userland CSPRNG, which is a terrible idea --- most Linux randomness flaws have stemmed from userland CSPRNGs. It also doesn't understand the difference between /dev/random and /dev/urandom.
There's also a sort of inexplicable walkthrough of bare Diffie-Hellman (ECDH is deferred), and not much coverage of authenticated key exchange, which is what in practice what systems using DH-style key exchange need.
Just a shotgun blast of random thoughts. I know it's early days for the book.
Other books in this space that I like: Aumasson's "Serious Cryptography" and David Wong's "Real World Cryptography".
The latter not being published until July 27. :-)
(I know this book is also not published yet, so I guess it's totally fair to suggest a not-yet-published book as an alternative to a not-yet-published book!)
For example, the section on Python libraries doesn't even mention the most commonly used Python crypto library (cryptography): https://github.com/nakov/Practical-Cryptography-for-Develope...
Similarly, the Java section essentially mentions a single, obscure library besides the JCE and Bouncy Castle: https://github.com/nakov/Practical-Cryptography-for-Develope...
There's also no mention of libsodium besides a bullet list item.
At first glance, looks like a solid book. I'll be going through it in more detail later.
Fun pop question for the audience - what protocols use AES-CFB mode? I see this mode come up every once in a while but outside of standards stating "This is how it works", what protocols and products is it useful in?
Modern systems all tend to use CTR-derived AEAD modes; if I wasn't doing a sealed AEAD, I'd probably do CTR+HMAC.
I give an example of this vs what age does in this article:
[0]: https://www.amazon.com/Mathematical-Cryptology-Computer-Scie...
This is important, since this book is intended for developers to use cryptography today.