Crypto people: “programmers really need to get better at using crypto!”
Also crypto people: “how DARE ye mere mortal even touch crypto!!!”
This doesn’t help. The only people who will listen to “don’t roll your own crypto” are the very people who ought to be learning how to do it. The arrogant types who should never touch crypto will ignore this advice and still write bad crypto.
The most effective thing would be to just tell programmers why crypto is hard in ways other code is not.
Crypto is hard because you can’t simply unit test for vulnerabilities. “Anyone can write a crypto system they themselves can’t break.”
For the majority of code it’s good code if it works and is fast and lacks things like memory safety bugs.
For crypto it can work perfectly and still be grossly insecure. The only way to tell is to deeply understand cryptanalysis and do academic mathy stuff.
As a result if you use crypto it’s best to write boring conservative crypto and use it the way pro cryptographers suggest. Try to use a peer reviewed library or if you can’t and must implement then try to ape a peer reviewed library exactly.
Don’t even try to invent new stuff in crypto unless your understanding is very thorough and don’t use anything new without peer review.
Edit: another example of abnormally hard code is distributed databases. They can be unit tested but adequately doing so is extremely difficult. It’s easy to write one that seems to work but loses data at scale or under edge case failure scenarios. Crypto is even worse.