Applied Cryptography Engineering
sockpuppet.org
sockpuppet.org
If you're interested in learning about the ideas in this piece via practical attacks you perform yourself, you should definitely check out his company Matasano's Crypto Challenge:
http://www.matasano.com/articles/crypto-challenges/
I've gone through the whole thing, and I can report that it's incredibly fun and incredibly enlightening. And you won't have to read a book to figure out that what Thomas is talking about here is legit.
There's also the implementation book on the Keccak NIST3 project website, same with their book on side channels and countermeasures.
There's also this: http://achs.cs.ucsb.edu/schedule.html which is a workshop in August on applied crypto and hardware which looks pretty amazing. University prof Patrick Schaumont always lists all upcoming applied crypto workshops https://twitter.com/pschaumont and he also has a lot of publications out: http://www.ece.vt.edu/schaum/pubs.html
However, you will learn a whole other approach of how to break all things crypto from the Matasano course.
As you say: persistence is key. We get a lot of emails. If you feel like you've slipped through the cracks, don't hesitate to ping us again!
(Each is people currently at that level).
We're still donating for every person who actually finishes.
Level 7 should be out ~nextweekish.
Sorry, I can't resist being a dick. Ignore me until I'm up to two weeks like the guy above...
It's one thing to explain the Weierstrass equation, the chord and tangent rule, and how group structure comes from that. But the details get really hairy really quick: anomalous curves, MOV/FR attacks, Weil descent, etc. I'm not saying it's impossible, but it's certainly very very hard to reasonably pull this off.
Another note about elliptic curves is that the safest choices are often not doable by developers because of external pressures. For example, ideally you'd want to use a curve (like Curve25519) that has complete addition formulas, so that you could avoid checks for explicit doubling or points-at-infinity, like you do with Weierstrass curves. Montgomery and Edwards curves allow this, but you can't use them if you need to support standard NIST curves, since they are not reasonably convertible to Edwards form (you can do it, actually, but the arithmetic is now in F_{p^3} instead of F_p).
(We have some basic problems, but you seem to know this stuff better than I do.)
I mean, yeah, it's an optimistic book. It talks about possibilities. How can someone to treat is as a developer reference is beyond me.
Err right. I'm black, Nigerian and have an interest + background in crypto...what's up with that man! :)
Anyway great coverage.
As an American, my impression is that the phrase "good red-blooded American" derives from the Cold War, or possibly earlier. For example, during the anti-communist movement of the 1950's, the term would be used judgmentally to distinguish from those who might be "pinko commies". C.f. "better dead than red".
Since the communist threat has obviously subsided, today I would interpret Ptacek's use of the term "like any red-blooded American" as both calling to mind a shared experience which many of us have had (growing up in America, reading Schneier's Applied Cryptography), as well as reminding us of the risk of failing to think beyond it.
Like the talk, the book will keep the structure of taking primitive X_i, showing why we don't just use a system based entirely on X_i, and instead also need X_{i+1}, and how eventually \sum X_i (perhaps excluding a couple) leads to complete cryptosystems, for some value of \sum (obviously, you can't just throw stuff together and expect it to work).
This blog post was great motivation for me. I will keep the aforementioned structure, but now I'm extra motivated to also add actual exercises instead of just showing it's broken :)
Thank you.
PS: I understand you're really busy, but there are few people I'd rather have as a reviewer.
Yep. I read it at... age 16? It was old by the time I got to it, since I'm relatively young, but I still loved it. It didn't give me a spark for crypto, I had the spark when I ordered the book, but it did a very good job of nurturing and kindling it.
> The biggest problem with Applied Cryptography isn’t the technical content, but the tone. It can’t decide whether to be a tour guide or a handbook.
That's a good summary. Personally, I've always thought of it as a hands-on encyclopedia.
Well yes my blood is red, I'm a programmer and I have an interest in cryptography. What makes you think everyone's American?
From the page:
> You should own Ferguson and Schneier’s follow-up, Cryptography Engineering (C.E.). Written partly in penance, the new book deftly handles material the older book stumbles over. C.E. wants to teach you the right way to work with cryptography without wasting time on GOST and El Gamal.
Plus a whole section at the end which starts with "If this stuff is interesting to you, here’s some additional reading:"