Anastasiia Voitova —  Use Cryptography; Don’t Learn It episode artwork

EPISODE · Sep 10, 2020 · 34 MIN

Anastasiia Voitova — Use Cryptography; Don’t Learn It

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Developers need to protect data, but should they need to become cryptographers to do it safely? Anastasiia Voitova, a software engineer working on data security at Cossack Labs, makes the case for boring cryptography: dependable libraries with clear, high-level interfaces and fewer opportunities for misuse. She explains the practical tension between encryption and application features such as searching, then walks through common mistakes in choosing algorithms, handling keys, and copying examples from the internet. Chris and Robert ask how developers can evaluate libraries and find trustworthy guidance. Anastasiia’s answer is to focus on the protection the application needs, choose tools designed for that job, and make the secure path easier than assembling cryptographic primitives by hand.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Anastasiia Voitova:→ Anastasiia Voitova at Cossack LabsMentioned in this episode:→ Cossack Labs→ OpenSSL→ GoFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Use cryptography without becoming a cryptographer01:43 Anastasiia’s route from development to data security04:36 The practical appeal of cryptography06:26 Data protection and searchable encryption10:34 What use cryptography, don’t learn it means12:07 Moving beyond don’t roll your own crypto14:02 Common mistakes in cryptographic design20:58 The risks of copying security examples21:46 Defining boring cryptography24:04 Choosing safer libraries and APIs28:22 Finding useful cryptography resources31:31 Practical advice for developers

Episode metadata supplied by the publisher feed · Published Sep 10, 2020

Embed this episode

Developers need to protect data, but should they need to become cryptographers to do it safely? Anastasiia Voitova, a software engineer working on data security at Cossack Labs, makes the case for boring cryptography: dependable libraries with clear, high-level interfaces and fewer opportunities for misuse. She explains the practical tension between encryption and application features such as searching, then walks through common mistakes in choosing algorithms, handling keys, and copying exam...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Anastasiia Voitova — Use Cryptography; Don’t Learn It

0:00 34:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 34 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 10, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!