Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Jean-Philippe Aumasson

This practical guide to modern encryption breaks down the fundamental mathematical concepts at the heart of cryptography without shying away from meaty discussions of how they work. You’ll learn about authenticated encryption, secure randomness, hash functions, block ciphers, and public-key techniques such as RSA and elliptic curve cryptography. You’ll also learn: - Key concepts in cryptography, such as computational security, attacker models, and forward secrecy - The strengths and limitations of the TLS protocol behind HTTPS secure websites - Quantum computation and post-quantum cryptography - About various vulnerabilities by examining numerous code examples and use cases - How to choose the best algorithm or protocol and ask vendors the right questions Each chapter includes a discussion of common implementation mistakes using real-world examples and details what could go wrong and how to avoid these pitfalls. Whether you’re a seasoned practitioner or a beginner looking to dive into the field, Serious Cryptography will provide a complete survey of modern encryption and its applications.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A working engineer's tour of modern encryption that treats cryptography as a practical engineering discipline rather than a mathematical abstraction—and shows, with real failure cases, why implementations break. Best for developers, security engineers, and technically curious readers who want to reason about algorithms and protocols instead of just calling a library. 【Book Arc】 - **Opening (~0%–10%)**: Sets the book's thesis—cryptography in theory is strong, cryptography in practice fails spectacularly—then grounds it in classical ciphers, key-length intuition, and the basics of probability used to quantify attack success. - **Early (~10%–32%)**: Builds the conceptual toolkit: computational security and (t, ε) definitions, attacker models (IND-CPA), security proofs and reductions, plus randomness—RNGs vs. PRNGs, entropy pools, and OS-level generators like /dev/urandom. - **Middle (~32%–50%)**: Moves into symmetric primitives: block cipher internals (Feistel schemes, AES rounds, S-boxes), modes of operation (ECB, CBC, CTR) and their pitfalls, then stream ciphers (RC4, Salsa20, hardware-oriented designs) with nonce-reuse and implementation failures. - **Late (~50%–80%)**: Extends to hash functions, MACs, authenticated encryption, and key management—key wrapping, password-derived keys, hardware tokens—alongside public-key techniques such as RSA and elliptic curve cryptography. (Excerpts do not cover the exact chapter boundaries here.) - **Ending (~80%–100%)**: Closes on protocols and forward-looking material: TLS's strengths and limitations, quantum computation and post-quantum cryptography, and how to choose algorithms and interrogate vendors. (Excerpts do not cover the closing chapters in detail.) 【Key Takeaways】 - **Cryptography fails in practice, not in theory** (Opening): the book's framing claim is that implementations by non-experts break in uniquely spectacular ways—CVE-labeled compromises, not abstract weaknesses. This is why the book pairs every algorithm with "how things can go wrong." - **Security is quantified, not asserted** (Early): computational security is expressed as (t, ε) bounds, and proofs are reductions to hard problems (e.g., RSA to factoring). Understanding this vocabulary lets you judge claims instead of trusting them. - **Randomness is a first-class engineering problem** (Early): RNGs give few unreliable analog bits; PRNGs expand them into long reliable streams via entropy pools. The Netscape seed failure and insecure /dev/urandom usage show how thin this layer really is. - **Modes of operation carry the real risk** (Middle): ECB leaks structure (identical plaintext blocks yield identical ciphertext), CBC and CTR each have distinct failure modes—padding oracles, nonce reuse—so choosing a mode is a security decision, not a detail. - **AES's design choices are load-bearing** (Middle): ShiftRows and MixColumns exist to diffuse changes across the state; omitting MixColumns in the final round is a deliberate optimization, not an oversight. Knowing why rounds work helps you spot broken variants. - **Never reuse a key–nonce pair** (Middle): stream ciphers are linear by construction, so keystream reuse makes XOR-based recovery trivial. This single rule explains a large share of real-world stream cipher breaks. - **Key storage is a trade-off, not a solved problem** (Late): key wrapping, on-the-fly derivation from passwords, and hardware tokens each shift risk—convenience versus exposure to weak passwords versus physical loss. - **Protocols and the post-quantum horizon matter** (Ending): TLS is where all these primitives meet reality, and quantum computation forces a migration plan. The book's aim is to help you ask vendors the right questions. 【Reading Tips】 - **Deep-read the "How Things Can Go Wrong" sections.** They are the book's spine; the algorithm chapters are context for them. - **Skim the classical-cipher and probability warm-ups if you already know them**, but don't skip the computational-security definitions—later chapters assume that vocabulary. - **Work the code listings.** The AES/CTR and ECB examples are short and demonstrate failure modes concretely; running them beats reading them. - **Treat the math as just-in-time.** Reductions and complexity-theory asides can be read for intuition on a first pass and revisited when a specific scheme needs justification. - **Keep a running list of "questions to ask a vendor"** as you read; the book explicitly aims to equip you for that conversation. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering roughly the first half of the book in detail (through stream ciphers and key management), with only outline-level signals for hash functions, public-key cryptography, TLS, and post-quantum material. Specific chapter titles, figures, and later-chapter arguments are not fully represented here.
Excerpt 1
C4 Implementation Weak Ciphers Baked Into Hardware FOREWORD If you’ve read a book or two on computer security, you may have encountered a common perspective...
View in text
Excerpt 2
(K || R) from random. Remember that How Things Can Go Wrong Encryption algorithms or implementations thereof can fail to protect confidentiality in many ways...
View in text
Excerpt 3
who can solve it, awarded by the Clay Mathematics Institute. This is discussed in more detail in Chapter 9. For example, consider the challenge of solving th...
View in text
Excerpt 4
and sent with the ciphertext in the clear. But unlike CBC’s initial value, CTR’s nonce doesn’t need to be random, it simply needs to be unique. A nonce shoul...
View in text
Excerpt 5
ts use hash values to prove that digital artifacts have not been modified; Bitcoin uses a hash function in its proof-of-work systems —and there are many more...
View in text
Excerpt 6
x construction Hash(K || M) will be the same for both keys. This problem is independent of the underlying hash and can be fixed by hashing the key’s length a...
View in text
Excerpt 7
cure cipher. Read the specifications written by experienced cryptographers for algorithms such as Keyak (an algorithm derived from Keccak) and NORX (designed...
View in text
Excerpt 8
as a hardness assumption, which is an assumption that some problem is computationally hard. This assumption is used when proving that breaking a cryptosystem...
View in text
Tags
AI categories
CybersecurityProgrammingTechnology
ISBN: 1593278268
Publisher: No Starch Press
Publish Year: 2017
Language: English
Pages: 312
File Format: PDF
File Size: 5.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…