Crypto Hygiene?

dmolnar dmolnar at
Mon Aug 11 16:45:21 EDT 2003

(also posted to sci.crypt in modified form)

At Usenix Security, Eric Rescorla pointed out that some of the
cryptographic flaws we have seen can be prevented by applying good
"crypto hygiene." My questions for the floor --

	* What is "good hygiene" ?
	* Where would I find it written down?
	* How do we develop good hygiene?
	Have we developed hygiene in the past that protects
	against as-yet-undiscovered attacks?

-David Molnar

