--- title: "Anastasiia Voitova — Use Cryptography; Don’t Learn It" url: https://appsecpodcast.com/anastasiia-voitova-use-cryptography-don-t-learn-it/ date: 2020-09-10 duration_seconds: 2086 guests: ["Anastasiia Voitova"] topics: ["Threat Modeling"] audio: https://www.buzzsprout.com/1730684/episodes/8122592-anastasiia-voitova-use-cryptography-don-t-learn-it.mp3 transcript: true --- # Anastasiia Voitova — Use Cryptography; Don’t Learn It *September 10, 2020 · 35 min* with [Anastasiia Voitova](https://appsecpodcast.com/guests/anastasiia-voitova/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122592-anastasiia-voitova-use-cryptography-don-t-learn-it.mp3) ## Show notes Developers need to protect data, but should they need to become cryptographers to do it safely? Anastasiia Voitova, a software engineer working on data security at Cossack Labs, makes the case for boring cryptography: dependable libraries with clear, high-level interfaces and fewer opportunities for misuse. She explains the practical tension between encryption and application features such as searching, then walks through common mistakes in choosing algorithms, handling keys, and copying examples from the internet. Chris and Robert ask how developers can evaluate libraries and find trustworthy guidance. Anastasiia’s answer is to focus on the protection the application needs, choose tools designed for that job, and make the secure path easier than assembling cryptographic primitives by hand. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Anastasiia Voitova: → [Anastasiia Voitova at Cossack Labs](https://www.cossacklabs.com/press-kit/) Mentioned in this episode: → [Cossack Labs](https://www.cossacklabs.com/) → [OpenSSL](https://www.openssl.org/) → [Go](https://go.dev/) Chapters: 00:00 Use cryptography without becoming a cryptographer 01:43 Anastasiia’s route from development to data security 04:36 The practical appeal of cryptography 06:26 Data protection and searchable encryption 10:34 What use cryptography, don’t learn it means 12:07 Moving beyond don’t roll your own crypto 14:02 Common mistakes in cryptographic design 20:58 The risks of copying security examples 21:46 Defining boring cryptography 24:04 Choosing safer libraries and APIs 28:22 Finding useful cryptography resources 31:31 Practical advice for developers ## Transcript *5,007 words · assemblyai* **0:00 Chris Romeo:** Anastasiia Voitova is a software engineer who works on data security solutions at Cosec Labs, making complex crypto easy to use in modern software. She joins us to explore the idea of boring crypto. She caught our attention with a talk at OWASP 24, where she encouraged developers to not learn crypto. You'll have to listen to understand her rationale. She explains mistakes folks make with crypto, boring crypto, and how to get started implementing boring crypto. We hope you enjoy this not-so-boring conversation with Anastasiia Voitova. Are you trying to build a security champions program? Everyone is these days. One challenge of rolling out security champions is, how do we educate all these new folks? Security Journey has your answer. We provide a security dojo environment with level-based security education that gives your newfound champions a path to follow. And the best part? It requires almost zero administration by you. Visit www.securityjourney.com. securityjourney.com to set up a demo and learn how you can use the Security Dojo to connect with your security champions. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and also co-host of this podcast. I'm also joined today by Robert. Hey, Robert. **1:33 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut, threat modeling architect. Good to be here with you. **1:37 Chris Romeo:** Definitely. We're going to be talking about people's favorite— one of their favorite things, cryptography. **1:42 Anastasiia Voitova:** Yay! **1:43 Chris Romeo:** We're going to make cryptography fun. Well, we're joined today by Anastasiia Voitova, and we want to jump right in. We want to hear your origin story. So how did you get started in security? What was your journey or your path like that brought you to where we are today? **1:59 Anastasiia Voitova:** Okay. Hello, hello. So my name is Anastasiia. And honestly, I started as a software developer. So I have like typical master's degree in computer science, nothing special, don't have PhD in cryptography. So important, if you have PhD in cryptography, this talk might be too easy for you, okay? And then when I was working on, I started from mobile applications. And at some point when I was doing like moving from stack to stack, from frontend, like mobile parts to backend, I understood that I kind of control the whole system now, and I'm the one who has access everywhere and into database, into production database with real users there. And I was like, that doesn't sound really good. And this was like a kind of beginning of my development journey. So I was good enough to be able to build full-stack applications, but that's it. On that point, I didn't think about security a lot. So I was like, hmm, this doesn't sound right. And I started to explore this topic. I started to dig into security from a developer perspective. And I was actually, for a couple of years, for 2 or 3 years, I was a contributor to open source cryptographic library, Themis, which— **3:27 Robert Hurlbut:** What is it? **3:28 Anastasiia Voitova:** Kind of moved me in my security journey forward. And at some point, I completely stopped doing regular software development and moved into security engineering, security architecture, and building secure systems, let's say it this way. So yeah, and cryptography is my interest since forever. And I'm especially interested in applied crypto, what we call it, not like creating new ciphers. Come on, there are special people who are to do that. No, I'm a simple, like, simple developer. I just want to use these things and use them correctly to protect the data, right? It should be easy. And here, here it's actually like, this is the problem lies. It's, it's not that easy as it looks like. And now I do have experience of building systems, breaking systems, and working on cryptographic libraries. So I kind of seen the same issue from different angles, and I speak a lot about usable, simple, and boring crypto. **4:36 Robert Hurlbut:** You know, that's interesting about some of your history there in terms of you as a developer, you were learning about crypto, and we're going to dig into this a little bit more, but what was it about crypto in terms of attracting you and getting into that? I mean, if you found some challenges or just the challenge itself? Because some people will, as Chris mentioned a moment ago, it's not a topic that everybody likes to talk about. Crypto always seems so mysterious and so strange, but it sounds like something that drew you in. Was it the challenge? **5:08 Anastasiia Voitova:** Well, for me it was more like, yeah, we can say challenge, but when I started, I didn't know the word security control. At that point, and I didn't realize after that. I actually understood that crypto, in terms of like data security, is a perfect like security control because you might not have all the other things, all the like other security controls in your system. But when your data is encrypted, it can't be magically decrypted, right? There should be something that actually decrypts this data. So when you use cryptography, you kind of build this like ultimate protection around your data, like a super cool security measure. And this is what makes it interesting from one perspective, but at the same time, but at the same time, it's so complicated. It's so easy to misuse. So you kind of have this powerful tool, but when you look on the market, you understand that not many developers, not many companies can use this tool correctly. So, it's complicated and scary, at the same time cool and super adventurous as a subject, as a tool. **6:26 Robert Hurlbut:** And with that in mind, what are some of the other challenges that you've seen in data security in particular? **6:31 Anastasiia Voitova:** Well, right now, I believe that cryptography itself, it's more like a a challenge in academia kind of thinking because we have already these industry-proven ciphers and typical scenario that's kind of fun, nothing important going there. But at the same time, we do have the regulations that are changing. And as companies that do something in the market, we have this pressure from data privacy regulations, which actually mean that, hey, we need to take care about users' data more, more, and more. At the same time, we want to build easy, scalable, understandable systems. So, sometimes these regulations versus typical engineering approaches, they're different. And in terms of cryptography, for example, We start talking about searchable encryption, right? Because regulations have this pressure that the data should be protected, encrypted. And it would be nice if the data could be encrypted all the time, but still, as developers, as architects, we would like to search through the data to do all these computations, but leaving the data encrypted. In a perfect world, leaving the data end-to-end encrypted. Imagine having a system with normal, standard end-to-end encryption, with ability to share data, with ability to search through data. I believe these are current challenges and this is something that companies start to explore right now. At least, it looks this from my perspective. Because I'm into data security, yeah. **8:31 Robert Hurlbut:** I remember, just like we mentioned searching, I can remember years ago as a developer and thinking about that. We want to search. We want to make sure it's fast, but at the same time, we need to make sure the data is confidential and protected and so forth. That's always been an interesting challenge. It sounds like it still is, and I'm sure it will be for a while. **8:52 Anastasiia Voitova:** It still is, and topics like homomorphic encryption, for example. Or search based on blind indexing approach. There are already applications that can do this and there are already production-ready apps because some of the schemes like homomorphic encryption, it may be too slow. It's still too slow for real users, for real use. But other schemes like search based on blind indexes, it's not slow. You can try it. Yeah, it's kind of restrictive, a little bit, but there is the software that implements that and you can use that software in your infrastructure to encrypt the data and being able to search through it. So yeah, this looks really cool. And post-quantum, right? Everyone is super excited about quantum computers and cryptography will be broken, obviously. So post-quantum crypto is also one of the topics that it's kind of interesting right now. **9:50 Chris Romeo:** Yeah. **9:51 Anastasiia Voitova:** From my experience, like from my opinion, we should not be scared. Like as developers, as security people, we should not be scared of quantum computers. But of course there will be some challenges. We will need to update the libraries and the ciphers, but it should be okay for most of the systems. **10:13 Chris Romeo:** So we found one of the talks that you did. That's how we got to this interview. And the name of the talk was Use Cryptography, Don't Learn It. And so it's great marketing, first of all, great marketing for the name of a talk because I was looking at that going, use cryptography, don't— wait, what? Don't learn it? I shouldn't know? **10:34 Anastasiia Voitova:** Okay. **10:34 Chris Romeo:** And so that was enough to catch my attention. So from your perspective, what do you mean when you say that phrase, use cryptography, don't learn it? **10:42 Anastasiia Voitova:** Think about the lamp. Right, the light bulb. When you turn on the light in your room, you just do like turn on, turn off. You use it. It makes your room light. At the same time, you don't need to learn what's actually going on, how electricity works, what is the construction of the light bulb to be able to use it. That's simple, on/off, and you have all you need. I believe that with cryptography, it should be the same for developers. But unfortunately, I can't say that it's already the same. That's why it's like a process, and a lot of things, like in terms of cryptographic libraries, right now is changing to this idea of light bulb, to be easy to use as light bulb. And this is what boring crypto basically is, which we will talk a little bit more later, right? So basically, my idea was that as a developer, if you are not a cryptographic engineer, if you don't work on new ciphers, on new ways to use ciphers, if you're a developer and you just want to do things right, you want to protect data, you want your system to be usable and fast and scalable, reliable, la la la la, you don't need to learn crypto. You need to use it as a tool. And you just like gradually dissolve. **12:07 Chris Romeo:** So I see how that would fit in with some of the— what I think of as more of the classic crypto advice we've been giving to developers for it seems like 20 years at this point, which is don't roll your own crypto, right? But it seems like that's consistent. You use cryptography, don't learn it, is consistent. It's not exactly the same message, but it's very similar in that when we say don't roll your own, we're talking about like don't go create your own algorithms and try to think you're gonna be smarter than everybody else because As a cryptographer, you're not going to be smarter than everybody else. There's people that will break the algorithm right away. So yeah, I love this idea though, and I'm going to borrow that expression about the light bulb. That's a great illustration of— **12:49 Anastasiia Voitova:** Yeah, feel free, feel free. That's actually, if you think about it, that's really, really great. And this is how these old oil lamps, if you still remember, like these oil lamps, you need to fill the oil to have this like How it's called, like a thread, right? To put it there, right? It's a whole process. And now instead, we have the light bulbs and we have this switcher. **13:15 Chris Romeo:** Just flip the switch. So we need crypto where we can just flip the switch. Yeah. **13:18 Robert Hurlbut:** We mentioned about that rolling, don't roll your own crypto. And yeah, we hear that a lot, but what are some other mistakes that developers might make or other folks might make with trying to implement Wow, that's a huge topic. **13:34 Anastasiia Voitova:** And first of all, I must admit that as a developer, I've done all of these mistakes, even worse, right? So learning from the best, right? At the same time, when I was already in a security engineer role, I've seen these mistakes being done. So this cycle is never-ending. I believe the first one is that as a developer, I would— let's assume we have this use case. As a developer, I want to protect data of our users. **14:02 Chris Romeo:** Easy. **14:02 Anastasiia Voitova:** I believe that the first mistake goes with what kind of data we will protect because there is— as a developer, I might not see the whole picture because I think about some valuable for business data because someone, some product manager will tell me about this data. At the same time, What those potential product managers don't know is about technical data, which also needs to be protected. All these accesses, keys, logs, all the things, right? So when we try to protect some data, it's easy to forget about certain data types, or it's easy to underestimate how certain data types are actually valuable. For the company and should also be protected. And this is what I often see, how people just omit some kind of data. This is a password, we'll protect this, but this is like user location or this is some access token, that's okay, that's fine. So I would start with scope. But let's move further. Let's assume that we do have Cool team. We understand what data is valuable for us as a company and what data is valuable for us technically. All good here. And we decided what kind of data to protect, like emails, for example. Let's protect user emails. Let's encrypt user emails. How will we encrypt them? Hmm, we probably need to use some cryptographic cipher for that, but which one to use? And here again, as software developers, they're not cryptographers, and no one should assume that they know and that they follow these crypto trends, right? They might not know which cipher to use. And unfortunately, the cryptographic libraries, they do have a lot of ciphers, especially if you say about OpenSSL. They do have a lot of old ciphers, deprecated ciphers, but they're still available. And there is nobody that will prevent developers from Googling on Stack Overflow and using this old cipher, right? Still, I still see systems that— okay, I still see systems that use Base64 as encryption. Let's move. Okay, so we decided, we decided, we Googled, and we decided to use— I know, let's use simple AES-GCM-256. Easy, simple, industry-proven. The next step is basically to select the crypto library that has this cipher And usually as a developer, I might use just native crypto libraries available in my language, in my stack, or I want to use, how it's called, like multi-platform crypto libraries that have realization for my language, right? And unfortunately, many crypto libraries were done by cryptographers that understand what they're doing. And as a developer, when I want to encrypt the data, I might see the API that consists of, I know, like 7 input parameters. The data, the key, key length, init vector, some padding, all these things that as a developer I need to understand what are these, what is IV. What is this init vector? What value should we put there? What is padding? What value to put there? What is key? What is the key length? Okay, that's easy to Google, but still, right? And even having good intent and even copy-pasting from Stack Overflow the nice-looking code, there could be actually some mistakes in this code and we know a lot of vulnerabilities came from misusing crypto libraries. So, okay, so data selected, cipher selected, trying to use cipher, need to dig through all these parameters. There are already libraries that give you like one-line API with like one or two parameters, data and key, and it's all good. If you see this library, this kind of libraries, try to use them because the chance of misusing them Are slower, are lower. But let's assume that we do all these things correctly and we have encrypted data and we have some key, right? The key keys are important. Keys are sensitive data we need to protect. And then again, often developers tend to put encrypted data together together with key somewhere. Hmm. You did all these things just to put key. Together with encrypted data. Why would you do that, right? So key management comes in place, and key management is super tricky. You know, there is another saying, encryption is easy, key management is hard, right? Because with keys, there comes a whole set of procedures, and there is like certain guidelines for that. For example, NIST Special Publication, I don't remember, 80057, if I remember correctly, Key Management Guidelines. They discuss what procedures should be, like what are key management procedures basically. Key generation, key rotation, key revocation, key expiration, key sharing. All these things you kinda need to think about in your system and build in from day zero Or at least think about it, how you will handle it. Because just having encrypted data and a key is not enough. You need to put this key in the correct place, you need to rotate it, you need to keep it from prying eyes, you need to back up it, and then backup, that's another kind of story, because when you backup encrypted data, make sure that you backup key to this data. But backup and key doesn't sound good, right? So yeah, there's a lot of tricky things that, that's a whole part of security software architecture. There's like the whole branch out, like a mix of typical software architecture and security engineering that can help you to build your system in a way to provide all these functions at the same time to be still fast, scalable, reliable, maintainable, and all these things. So yeah, that's a lot of things going on and a lot of mistakes developers can do. when they just wanna protect the data. **20:58 Chris Romeo:** Yeah, and to your point about Stack Overflow, you know, we know Stack Overflow could be dangerous just in general from developers going copying pieces of code. And I've seen various academic papers that have analyzed the number of flaws that exist in Stack Overflow code. And they've also analyzed how people tend to rate, or they tend to give the best answer to the people with the highest ratings on the platform. So it isn't even that they have the most secure solution, that they're the highest-rated person on the platform. And so definitely some challenges there. But as you went through and we're talking about all those different mistakes or challenges, I'm thinking to myself, like, this is a threat model for using crypto. Wrong scope, bad algorithm selection— these are all threats. Like, your threat— **21:44 Robert Hurlbut:** Everything is threat modeling. **21:46 Chris Romeo:** Everything is threat modeling. Threat modeling is life. Yeah, that's our new— I'm gonna put that on a t-shirt. Threat modeling is life. So you use the term boring crypto. And so I'm curious, what do you mean when you say boring crypto? **22:00 Anastasiia Voitova:** Well, in this context, boring means good. So boring crypto is like best of the best of the best crypto, right? It's actually the term— I didn't invent the term. I learned it from Daniel Bernstein from his talk in 2015. And by boring crypto, he originally meant that, first of all, this is like an idea. So, this is some framework, the idea that crypto should be boring in a way that it's not exciting to use, it's very boring to use. Just easy to install, easy to use, easy to update, nothing fun going on. It's just yet another brick in your system wall, right? Super easy, super understandable, as exciting as a light switch. Yeah. And now we use this term boring crypto to distinguish just crypto libraries that are being developed, again, usually by cryptographers. And usually a lot of crypto libraries, they already have this history, so they use a lot of ciphers, they provide you access to many ciphers that are already old and outdated, la la la. And boring crypto libraries that kind of hide all the details of implementation and give for developers, for their end users, a very high-level API. Easy to use, hard to misuse. It's really complicated to make all these mistakes when instead of 7 parameters in a function, you have 2 parameters, data and key. It's not like, okay, you still can make mistakes, but at least it's kind of easier. So, and many libraries, if you look on the GitHub, for example, right now, many cryptographic libraries start to use this term, like, we are boring crypto library, in a way to illustrate, like, we are safe, that's okay, you don't need to know cryptography to be able to encrypt the data. **24:04 Robert Hurlbut:** So, that sounds like sort of an analogy, I guess, if that I've heard about in terms of users when they're trying to figure out all the security configurations. And if you can make it simple to make sure they don't trip themselves up, if you will. Similar here, you're helping developers, give them a simple API, encrypt, decrypt, maybe data key, very, very simple. So it really helps them be successful without having to be too complicated or figure out something too complicated to get the job done. So, I like that. That's a fantastic approach, I believe. How would we find that? How would a developer find those kinds of good APIs and libraries that are available like that? **24:54 Anastasiia Voitova:** That's super easy. As developers usually do, just look at the amount of stars on GitHub, right? Yeah, I wish. I actually learned during my maintainer, contributor to the Open Source Crypto Library career, I actually learned that people don't like to put stars on crypto library. No, they prefer libraries with nice animations, libraries that do something visual and nice. A crypto library, what kind of creature is that? So actually, if you look on the Git, honestly, no jokes, if you look on GitHub, on the popular crypto libraries, they don't have a lot of stars. It's like, this is the segment of developers don't really want to touch. However, fortunately, I can give a couple of advice how to try to select boring crypto library. First of all, I would say that take a look on this native platform libraries available for your language or for your technical stack and look on which ciphers this library provides. And if it provides old ciphers, that's like a question mark, right? If this is the API, looking on this API, you see a lot of parameters, a lot of things going on there, that's a question mark. In some languages like Go, for example, they have amazing, amazing native crypto library. More boring. Or for example, Apple World, they are updating their crypto library right now. So they kind of have this old CommonCrypto crypto library, typical crypto library, 7 parameters, 8 parameters for each function. And now they're switching to new one, CryptoKit library, which is written in Swift, and they have this encrypt 2 parameters, decrypt 2 parameters, easy as that. At the same time, but these are like platform-dependent libraries, right? If you're looking to, if you're looking to use cryptography on multiple platforms, for example, you are doing applications that works on multiple platforms, take a look on multi-platform libraries like libsodium. libsodium is super popular. It's also named NaCl. Like, you know, not really, yeah, not really chlorine, right? Yeah, so that's super popular. Or take a look on Temis, for example. That's another multi-platform crypto library. The difference between them is like different sets of algorithms and different ideas. As far as I know, Libsodium is like core library and the wrappers, the language wrappers, are being developed by different people. So there is a chance of inconsistency between them. And for example, Temis as a crypto library, it's been developed by the same group of people, it's the same repository, so it's kind of compatible between languages. And yeah, I would suggest to take a look on native libraries, to review the API, if it looks good, like use that. If it looks suspicious, try to use these multi-platform libraries. **28:22 Chris Romeo:** So when you think of resources for someone who may be relatively new to Boring Crypto, you know, I know we just talked about how to pick a particular library, but are there blogs or websites or resources, books that you would point people towards if they said, hey, I want to learn more about this whole idea of boring crypto and just want to learn more about using cryptography, not learning it? **28:48 Anastasiia Voitova:** That's tricky. I can easily point out resources that are useful for learning cryptography, right? But use— like, only for using cryptography only, that's really tricky. I believe that the best would be to be subscribed on blogs by companies that have this idea of boring and usable crypto, or let's say boring and usable security. Because security tools, cryptographic tools, in a way, they are security tools, right? And we can extrapolate and we can look on these typical security tools from the same perspective. If this is some tool that requires a lot of customization, that doesn't have secure-by-default parameters, maybe it's too exciting, maybe it's not as boring as it should be, maybe it leaves us a certain set of potential mistakes of using this tool and misusing this tool. So, I would recommend to follow the blogs of companies that do security tools and that promote this idea of Usable Cryptography. To have like a good general overview, I really like the book from Jean-Philippe Homos on serious cryptography. That's a cool book and it has, it has description of crypto starting from basics, from randomness and going through all the ciphers, all the things including post-quantum Cryptography. I also can recommend certain GitHub repositories, for example, Awesome Cryptography or Awesome Crypto Papers. The first one is a collection of tools, books, links, libraries, and the second, Crypto Papers, is a collection of papers. And this is cool that you can actually read those, you know, first papers that describe, for example, GCM. mode from IASGCM. So like classical original papers, at the same time you can read new papers on lattice or on zero-knowledge proofs or something like it, you know, kind of new things in cryptography. I will put— I will give all the links. I think you'll be able to get the links and check on yourself. **31:17 Robert Hurlbut:** So let's say We appreciate everything you've mentioned here to us. I've heard about boring crypto before, but I never really thought about it, like boring SSL. I remember seeing that, and I never really put the two together. **31:30 Anastasiia Voitova:** Yeah, boring SSL. **31:31 Robert Hurlbut:** Yeah, I never put the two together until today, so I appreciate you mentioning that. What are some maybe key takeaways that if a developer is saying, hey, you know, I'm now reviewing my choice of algorithm or Or I'm maybe implementing a new system. What are some perhaps key takeaways or even call to action for developers as they're starting to think about this? **31:56 Anastasiia Voitova:** I would say try to use boring tools, right? Instead of spending time on learning cryptography or figuring out how to use, like, how to do your things with normal, I don't know, cryptographic tools, or like usual, better spend this time trying to find the boring tool because this will actually save your time later during implementation, during testing, or maybe even save you from security mistakes and potential vulnerabilities. Because that's, you know, the idea behind boring crypto things is that some parameters are already being handled by people who know how to do this instead of you. And if you don't have this background, that's kind of nice to trust someone that does. I would also, uh, I would, I know, I would mention, let's, let's make a small like turn here regarding Boring SSL. You know the original story, right? That it was like a fork of OpenSSL initially, and then yeah, yeah. Yeah, yeah, yeah. So the idea behind Boring SSL was similar, that in OpenSSL there is a lot of ciphers and like old and a lot of potential, you know, problems that couldn't be fixed during many releases. So Google team just, you know, forked and made their own SSL. And right now we have OpenSSL, Boring SSL, LibreSSL, BearSSL, And all the other asset sales. That's a lot of things going on. **33:40 Chris Romeo:** Anastasiia, thank you for being with us and for educating us about Boring Crypto and using cryptography, not learning it, all these good things. I know I've learned a bunch of stuff, and Robert already shared his perspective on, you know, you helped us to connect a lot of the dots here. And so thank you very much for sharing. this time with our audience, and we look forward to chatting again with you in the future about some other topic. **34:05 Robert Hurlbut:** Yeah, definitely. **34:06 Anastasiia Voitova:** Yes, sure. Thank you for inviting me, and I hope it was useful. **34:10 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security. security-podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/anastasiia-voitova-use-cryptography-don-t-learn-it/