If we were talking instead about people operating their own pharmacies, or doing their own home electrical work, nobody would bat an eyelash.
If we were talking instead about people operating their own pharmacies, or doing their own home electrical work, nobody would bat an eyelash.
More seriously, as someone else says elsewhere, it seems better to confront the problem head on, and help people figure things out in terms of what's a really bad idea, what you can reasonably hope to piece together yourself using off the shelf pieces, and what the heck: what to do to get more experience if you're interested in different areas of crypto and security. I mean, those "perfect" people who write stuff had to get their start somewhere, right? The author of this particular piece strikes me as correctly cautious - "I'm not smart enough" - or something like that. Should crypto writing be left to people who feel like they are pretty hot shit? Somehow that doesn't strike me as a good way to decide. What are some materials you should master in order to do X, Y, or Z with some degree of certainty?
I don't know much about crypto and security stuff, so I'm not the one to write it, but I think a more detailed article might be more beneficial, because "don't touch crypto stuff" is awfully vague. For instance, utilizing GPG or SSL seems like it makes sense for some situations, and that there are a fair number of people who can make them work ok. Designing your own crypto algorithm and implementing it in C probably is not something most people ought to do outside of experimenting for their own interest. But they why's and how's ought to be explained some too. I guess what bugs me about some of these articles is that they feel a bit cargo-culty in the sense of worshiping the security gods that you must make obeisance to rather than simply explaining some facts about various aspects of crypto and security.
One more thought on the subject: if people don't understand why some things are bad ideas, how can they explain it to their bosses asking them to do something silly?
Just pick up a $10 book at your local Home Depot and if you can read and follow the simple instructions and guidelines inside, you'll be able to do most simple electrical work.
Some electricians may say that it's foolish to do your own electrical work unless you're a trained/certified electrician.
Lots of people do most of their own electrical work without problems, and only hire expert electricians for the really risky or technical parts such as connecting to the utility companies or dealing with really high voltages.
But I'm particularly interested in David's response, because he raises this concern pretty regularly.
Something that explains how to use a high level cryptography library safely. A guide that recognizes that the reader is probably stupid enough to create a buffer overflow if he even goes near C++. A guide that assumes the reader will use rand to generate keys if able to and not reminded multiple times not to. A guide for people who have never heard about side channels. A guide that seriously cautions not to hand over the plaintext to Eve even if she asks nicely.
In all the stories you read about some generalist developer blowing their users' feet off with bad crypto, what you're reading about is someone reinventing these libraries with vanity crypto.
keyczar::Keyczar* crypter = keyczar::Crypter::Read(location);
if (!crypter)
return;
crypter->set_compression(keyczar::Keyczar::ZLIB);
std::string input = "Hey Alice, here is Eves message: [quote]"+superescape(evemessage)+"[/quote] Your Bob";
std::string ciphertext;
bool result = crypter->Encrypt(input, &ciphertext);
Ooops because, http://arstechnica.com/security/2012/09/many-ways-to-break-s...(Just don't use compression with your encryption and avoid the issue entirely).
Spill a little dimethylmercury? Welp, you're dead.
Sign something with your DSA key using a dodgy PRNG? Welp, you're dead.
Not always true! Your simple change like adding a GFCI outlet or a socket somewhere may not behave as expected if some idiot 30 years ago did something like attach ground to the neutral wire. Or, unbeknownst to you, that old line that you make a pigtail with may be an aluminium wire, which requires specific hardware to safely splice. 5 years later, the trivial act of installing a ceiling fan could be a fire.
Crypto is similar, there are lots of icebergs lurking around. That doesn't mean that you need to fear it, but you do need to know what you are doing, or take measures to validate that what you're learning and applying is accurate.