26 karma · joined May 6, 2022
I can't agree with this; Destroying internet security is an excellent reason to build a new machine.
See Jason Donenfeld's authoritative talk on the Linux RNG for details: https://youtu.be/-_yzaSp2xtY
Additionally, the best attack on ECDLP (Pollard's rho) is much easier to understand than the best attack on RSA (the number field sieve).
For the design and internals of hash functions? The finalists for the SHA3 competition have extensive design documentation. There's an archive at https://web.archive.org/web/20170829225940/http://csrc.nist....
Cryptographic hash functions are designed to resist existing attacks, so you'll want an understanding of differential & linear cryptanalysis, as well as a variety of algebraic attacks. I don't know of a good textbook on the subject, so you might find yourself searching keywords on https://eprint.iacr.org/
70% of security bugs are memory safety issues. That's a lot of real problems.
> It has a lot of irks, but the problems people run into are problems that others already solved, a thousand times, over the last half century, in many different ways for many different iterations of the language.
People run into memory safety issues more often in new C++ code.
https://www.chromium.org/Home/chromium-security/memory-safet...
https://security.googleblog.com/2021/09/an-update-on-memory-...
https://github.com/microsoft/MSRC-Security-Research/blob/mas...
https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI...
https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...
https://advocacy.consumerreports.org/research/report-future-...
https://alexgaynor.net/2020/may/27/science-on-memory-unsafet...
https://github.com/google/sanitizers/blob/master/hwaddress-s...
https://security.googleblog.com/2022/12/memory-safe-language...
[0] https://github.blog/2021-11-15-highlights-from-git-2-34/#tid... [1] https://git-scm.com/docs/git-config#Documentation/git-config...