ciphergoth: (Default)
[personal profile] ciphergoth
Just read this story on Slashdot, so in curiosity I downloaded the paper. And I have to echo and extend comments Peter Gutmann made about the state of crypto under Linux: when you hear about a product that uses crypto, open source, Linux based or otherwise, just assume that the crypto is woefully cack-handed rubbish from someone who's read Applied Cryptography if that.

ssh v2 is mostly OK. TLS (SSL v3.1) is mostly OK. GPG is mostly OK. IPSec is mostly OK. I don't know of anything else that people in the field think well of.

Date: 2003-09-29 08:21 am (UTC)
babysimon: (Default)
From: [personal profile] babysimon
What else is there?

Date: 2003-09-29 09:43 am (UTC)
From: [identity profile] pavlos.livejournal.com
Is your point that OSS crypto is especially bad, or no better than CSS?

Pavlos

Date: 2003-09-30 06:02 am (UTC)
From: [identity profile] giolla.livejournal.com
Of the 4 you list of course at least 2 have thier roots in CSS. I can't recall where IPSec sprang from but it has had a fair amount of commercial input.

GPG is really an odd one out having started life as OSS drifted into CSS and then back out.

/* Obviously I am looking back to where those 4 first originated from, SSL, SSH, PGP, Sunscreen? */

Profile

ciphergoth: (Default)
Paul Crowley

January 2025

S M T W T F S
   1234
5678 91011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Dec. 25th, 2025 02:41 am
Powered by Dreamwidth Studios