Dhole Moments
Read post

Cryptography Engineering Has An Intrinsic Duty of Care

Cryptography engineers have a duty of care to their users that many are failing to meet. Three case studies illustrate the problem: insecure AES implementations in aes-js/pyaes with cavalier developer responses, a research paper eviscerating LastPass, Bitwarden, and Dashlane's cryptographic security, and Matrix's dismissive response to disclosed vulnerabilities. The core failure is that most cryptographic software lacks clear threat models, vague security goals, and poor transparency about maturity. A minimum bar is proposed: write obviously secure ('boring') code, state security goals and assumptions explicitly, and be transparent about project maturity. Being open source does not absolve developers of responsibility when their cryptographic code is widely adopted.

    #security#open-source#cryptography
Feb 25•9m read time•From soatok.blog
Post cover image
Table of contents
Three Little DislcosuresResponsibility and CryptographyWhat Can We Do?
367 Impressions
Dhole Moments's image
Dhole Moments

Soatok is a blog or publication authored by Soatok Dhole, a security researcher and privacy advocate...

26 Followers

•

119 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard