The Matasano Crypto Challenges
matasano.com
matasano.com
You'll want to be able to code proficiently
in any language.
That should probably be: You'll want to be able to code proficiently
in *some* language.
I should think no one can code proficiently in every language, and to me, that's what the first implies."any 1 [ usu. with negative or in questions ] used to refer to one or some of a thing or number of things, no matter how much or many"
A reminder: $20 to Watsi for each person who finishes all six sets.
Can't wait to finish real work so I can focus on banging out code for round 1.
Actually, looks like an email mixup. I didn't reply directly to the more recent email and composed a fresh mail to us@cryptopals.com which doesn't work (although I did CC the other address as requested). Just forwarded my submission.
Edit: Just got set 2.
They must have a huge spike in requests to go through, plus the people completing sets 1 and 2. I would expect waiting times to drop as fewer people complete the advanced sets.
i "knew" some of attacks were possible, but had no real idea of how to go about exploiting them "for real" - this course works you through practical applications (and i found it to be pitched at an almost perfect level - it moves fast enough to be interesting, but not so fast you get lost).
they're quite meaty - doing one email (out of the 6) takes at least a day for me (but there's also some slack - you've got quite a bit of freedom and i think you could spend more or less time, depending on exactly what you choose to do.)
i haven't needed any deep technical knowledge or hard maths (but i already knew, for example, what a "block cipher" was and what "modes of operation" were, even if i couldn't tell you which did what without looking at wikipedia). the hardest part has just been "bookkeeping" in the code - tracking which offset in the array of data i am modifying, etc. the usual programming details.
so this is for interested amateurs - i don't think the nsa is going to be very excited learning who has completed the course...
(also, fwiw, i'm using python 3.3 (the new "yield from" is very useful when writing code that modifies sequences) and it's plenty fast enough so far)
Yes. Though: I studied cryptography as part of mathematics in university, and while we studied much more sophisticated attacks and ways to break your ciphers, we never actually ended up coding up the breaks even of comparatively trivial attacks.
I'd appreciate leads on places we should expand our coverage. Sean is already working on set 7, and we're pulling attacks out of the recent literature to do that.
Worth mentioning: we're not cryptographers.
"I’m not actually a supporter of the general adage “never roll your own crypto.” I believe that cryptography is a fairly closed system, and that it’s relatively straightforward to learn how to carefully use cryptographic primitives to build protocols securely. Certificate validation, on the other hand, is something that I would recommend people avoid doing themselves, if possible. It’s mired in cruft and gotchas."[1]
Moxie covers a few examples in the link, but it would be interesting to see some more along those lines.
[1] http://www.thoughtcrime.org/blog/strongtrustmanager-mitm/
Edit: I read this comment out of context. Sorry. Obviously, I asked for examples of flaws we could cover. Thanks for offering one up.
One thing I remember breaking (in theory) in university was a crypto-system based on the knapsack problem. But it is not in use in practice (because it has been broken). I don't know whether you included it.
As Hegel said, "The familiar is not understood precisely because it's familiar." Das Bekannte überhaupt ist darum, weil es bekannt ist, nicht erkannt.
I live this every day as a teacher. Students believe they understand, say, linked lists because they can recite all sorts of Linked List Facts™. It's not until you put them in front of a problem with a linked-list-shaped hole that they truly come to understand (erkennen).
Unfortunately English doesn't have the precise distinction that German does, so the translation is a little confusing. To an English speaker "familiar", "known", and "understood" are almost synonymous.
Many programmers I know use the word "grok" as a stand in: http://en.wikipedia.org/wiki/Grok
Nobody is going to come out of these challenges qualified to pick SHA-4 or AES-ng, or for that matter, prepared to design a new cipher or even a novel crypto construction. That's not the point of the challenges.
But we're covering what I think might be an odd corner of cryptography. Our approach to crypto is from a software security perspective. In a similar sense as 2013 software security researcher might be able to tell you a great deal about how Javascript objects are allocated a browser but not have any idea about best practices for organizing actual working Javascript code, we're covering an idiosyncratic set of implementation details but leaving all the theory out --- not least because we don't have the theory background.
Me, too. The courses I took were much more theoretical--lots and lots of number theory. I enjoyed them, and I enjoy your challenges, too.
The theory is fun, and I learned enough to understand some interesting attacks, but at the level of courses I studied the material at, we did not come up with any new attacks.
The distinction is a bit like theoretical computer science versus actually writing a programme.
P.S. I'll looking through material from my old university and see if I can find anything interesting.
About 1 out of every ~200 people we mail refuses the mail (at SMTP) for one reason or another, so if you're running your own email server, make sure it'll accept mail from MATASANOCRYPTOPALS.COM --- note that's not the domain you sent to.