Cryptography: Security engineers announce Project Wycheproof
“Many of the algorithms used in cryptography for encryption, decryption, and authentication are complicated, especially when asymmetric, public key cryptography is being used," said Peter Bright on Monday in Ars Technica. "Over the years, these complexities have resulted in a wide range of bugs in real crypto libraries and the software that uses them."
Bright was giving us a bigger picture view in light of the good news from Google. On Monday Google announced the release of Project Wycheproof. This should ease some pain.
The project involves a set of security tests that check cryptographic software libraries for known weaknesses. Daniel Bleichenbacher and Thai Duong, security engineers with Google, announced the test suite on the Google Security Blog. They said this was "a collection of unit tests that detect known weaknesses or check for expected behaviors of some cryptographic algorithm."