@dequbed
Finding materials on how to roll your own crypto (I just mean securely implementing existing algorithms, not even designing a novel one) is also really hard! I haven't found anything like "common pitfalls and how to avoid them". Of course the standard should hopefully document which parts need to be done in constant time or anything, but it still feels like there's a lot of assumed knowledge.
(This post is a request for any such materials if someone knows of them)