Crypto investment advice
Profit 100% guaranteed
Do you want to invest time and energy in learning cryptography?
Like for sport and music you’ll need:
Good teachers
Learn the fundamentals
Know the classics
Practice
Let’s go.
Good teachers
I can’t not recommend my own book Serious Cryptography: it goes from the basic notions and primitives to modern applications like post-quantum cryptography and threshold signatures. It will teach you the fundamental concepts without much mathematics.
There are other great books and resources:
Book The Joy of Cryptography by Mike Rosulek: more mathematically formal and gives you the foundations for doing academic research.
Book Real World Cryptography by David Wong: great illustrations, with exercises and source code.
Class Applied Cryptography by Nadim Kobeissi: includes lecture slides and reading list, and even quizzes.
Those three will get you a long way.
Learn the fundamentals
Many want to jump straight into the cool stuff like zero-knowledge proofs and post-quantum crypto before mastering the basics. As a result, they only get a shallow understanding and misunderstanding of more complex topics.
Cryptography is a broad field, no one masters every subfield—while I know symmetric cryptography and cryptanalysis well, I couldn’t write a protocol's security proof for my life. But you should at least know the foundational notions and tools.
Here’s a non-exhaustive list:
Probability: randomness, discrete distributions.
Linear algebra: vectors and matrices, linear transforms.
Commutative algebra: groups, rings, fields.
Elliptic curves over finite fields, as used in crypto.
Complexity theory: concept of reduction, NP hardness, asymptotic vs concrete complexity.
Hard problems like factoring, discrete log, learning with errors.
Basic security notions, from confidentiality and indistinguishability to non-repudiation and deniability.
Cryptography primitives and their security properties, from stream ciphers and pseudorandom functions to trapdoor functions.
Security notions and attack models. For example, what is secure encryption?
Differential cryptanalysis, the broad class of techniques used to attack symmetric schemes from Enigma to AES.
Know the classics
By classics I mean:
The legacy systems that modern crypto comes from,
The cryptography underlying the current IT infrastructure,
Important research papers and publications.
Disclaimer: These lists are highly subjective, and I’m more familiar with symmetric than public-key cryptography.
Protocols
You don’t need to know those protocols in-and-out but at least what they do (or did) and how they work. Studying older protocols and their limitations helps in not repeating their mistakes.
I probably forget important ones:
TLS, from the first SSL versions to v1.3.
SSH (RFCs 4251, 4252, 4253, 4254).
The IPsec suite.
Kerberos.
OTR and how it evolved to the Signal protocol.
Tor’s onion routing.
Wireguard.
Software
You at least need to know what they do (or did), bonus points for looking at their source code:
Linux kernel PRNG.
PGP/GnuPG.
OpenSSL as a command-line utility, its libraries libcrypto and libssl, the fork BoringSSL
Disk encryption systems like Filevault and LUKS.
Libraries: NaCl and libsodium, Go's crypto package, the Rust Crypto project, Python’s cryptography package.
Attacks
Learn the major public cryptographic failures so you don’t reproduce them:
Heartbleed, of course.
Flaws in TLS 1.0 to 1.2, which started the era of branded vulnerabilities just before Heartbleed: BEAST, CRIME, Lucky13, BREACH, POODLE, FREAK, Logjam, etc.
Dual_EC_DRBG.
The Debian OpenSSH PRNG (CVE-2008-0166).
The PlayStation 3’s ECDSA and its reused nonce.
Attacks on the WEP protocol
Papers and essays
Oldies but goodies, examples:
Bruce Schneier’s essays, including Security Pitfalls in Cryptography and Why Cryptography Is Harder Than It Looks.
New directions in cryptography, the Diffie-Hellman paper.
Probabilistic encryption & how to play mental poker keeping secret all partial information by Goldwasser and Micali.
The RSA paper, and Twenty Years of Attacks on the RSA Cryptosystem by Boneh.
How to Share a Secret by Shamir.
Another Parallel Collision Search with Cryptanalytic Applications by van Oorschot and Wiener.
The Curse of Cryptography Numerology by Griggs and Gutmann.
Another Look at “Provable Security” by Koblitz and Menezes.
Dan Bernstein papers:
Practice
To learn crypto, you do crypto. For example:
Do the exercises from David’s book and Nadim’s class.
Design your own cipher and break it.
Implement primitives and protocols.
Read implementations of complex protocols, compare them to their specifications, look for discrepancies and for what the specifications don’t say.
Use OpenSSL and its libraries, it’s an experience.
Featured image: Future.