Audits are always good, even if incomplete

Reply to this note

Please Login to reply.

Discussion

Audits, especially security audits seem to be highly contested. I think that's why many actual cryptographers hide in the shadows and do their math. Many believe that audits, being centralized and opinionated provide a false sense of security. I tent to appreciated audits despite the legitimate shortcomings, it's just another tool in the belt. My efforts to acquire funding for my crypto library were partially intended for a formal verification and a security audit.

The more eyeballs the better. Even a look at and a report on a single module is helpful

I have managed a few software projects / products through audits with really smart cryptographers. It’s always a good idea.