Maybe this would make more sense if you could describe what was madness-making about cipher negotiation.
Maybe this would make more sense if you could describe what was madness-making about cipher negotiation.
JCE implementation (mostly related to scope, era, etc.) -- admittedly, we only needed a non-US JCE for a few specific things, as part of an overcomplicated financial transfer system.
PGP/OpenPGP; there were lots of reasons this sucked, but multiple ciphersuites didn't help at all.
Free S/WAN was painful too (and really most of IPsec), but it's an example of the higher level problem of "too many layers of indirection and abstraction", not "too many algorithm choices."
(Poking at OpenSSL internals as a consumer of the library and trying to get it to work with some hardware shit made me mostly want to die, too, but part of that is my inferior C skills, and other things specific to OpenSSL and not to the overall concept of multiple algorithms)
OTR, ecash protocols of various types, etc. which used hardcoded algorithms were comparatively painless.
ssh is probably a good counterexample -- relatively flexible choices, although the big shift from v1 to v2 fixed a lot more things than just algorithms.
What can I do to protect myself? Do you forsee projects like these responding to the concerns in the presentation in a timely manner?