[Cryptography] Heartbleed and fundamental crypto programming practices

Dave Horsfall dave at horsfall.org
Sat Apr 26 17:37:42 EDT 2014


On Sat, 26 Apr 2014, Jerry Leichter wrote:

> ASN.1 was designed at a time when networks were slow and every bit 
> counted.  It's an *extremely* tight encoding.

Tell me about it...  In a previous life I supported OpenLDAP, and from 
time to time I had to go right down to the wire.

Whoever designed ASN.1 must have been smoking something.  Is there a 
reason to keep on using it?

ObCrypto: Protocols really need to be easily verified i.e. you are 
actually sending what you intended to send.

-- Dave


More information about the cryptography mailing list