Carelessness versus craftsmanship in cryptography
Summary
Trail of Bits highlights the distinction between carelessness and craftsmanship in cryptography by examining a default IV vulnerability in aes-js and pyaes, and the remediation in strongMan VPN Manager. It uses this narrative to argue that secure software comes from thoughtful fixes, modern cipher modes, and transparent updates.