Aaaah damn I need to write a cohesive text about why “Don't roll your own crypto” is a horrible statement and has done nothing but stolen two generations of sorely needed cryptographers away from us.
It's a statement akin to “Don't build your own bridges”! It's stupid and wrong and doesn't actually touch the core of the issue.
@dequbed Finding materials on how to roll your own crypto (I just mean securely implementing existing algorithms, not even designing a novel one) is also really hard! I haven't found anything like "common pitfalls and how to avoid them". Of course the standard should hopefully document which parts need to be done in constant time or anything, but it still feels like there's a lot of assumed knowledge.
(This post is a request for any such materials if someone knows of them)