flâneur — a map of the web's best reading

Database Cryptography Fur the Rest of Us - Dhole Moments

soatok.blog · 6,328 words · saved by 1 readers

Earlier this year, Cendyne wrote a blog post covering the use of HKDF, building partially upon my own blog post about HKDF and the KDF security definition, but moreso inspired by a cryptographic issue they identified in another company’s product (dubbed AnonCo). At the bottom they teased: Database cryptography is hard. The above sketch is not complete and does not address several threats! This article is quite long, so I will not be sharing the fixes. If you read Cendyne’s post, you may have nodded along with that remark and not appreciate the degree to which our naga friend was putting it mildly. So I thought I’d share some of my knowledge about real-world database cryptography in an accessible and fun format in the hopes that it might serve as an introduction to the specialization. Note: I’m also not going to fix Cendyne’s sketch of AnonCo’s software here–partly because I don’t want to get in the habit of assigning homework or required reading, but mostly because it’s kind of obvious

Earlier this year, Cendyne wrote a blog post covering the use of HKDF , building partially upon my own blog post about HKDF and the KDF security definition , but moreso inspired by a cryptographic issue they identified in another company’s product (dubbed AnonCo). At the bottom they teased: Database cryptography is hard. The above sketch is not complete and does not address several threats! This article is quite long, so I will not be sharing the fixes. Cendyne If you read Cendyne’s post, you may have nodded along with that remark and not appreciate the degree to which our naga fri

Explore this link on the map →

related reading