3 ms·
Except that security standards are mostly driven by compatibility with all sorts of edge cases (ancient versions of software! COBOL-bound CAs! tiny smart cards!
by arielb1 10y ago
Except that security standards are mostly driven by compatibility with all sorts of edge cases (ancient versions of software! COBOL-bound CAs! tiny smart cards! huge distributed systems!) that are probably not relevant to your case and create big random security holes.
If you have a reasonable way of distributing software updates, signed-DH with an AES-based AEAD with termination detection for transport authentication, and a signed hash tree for data authentication, is going to be more secure than RANDOM_SECURITY_STANDARD.
Thankfully, there are some good well-written implementations of that (https://www.tarsnap.com/spiped.html https://www.tarsnap.com/spiped.html, https://nacl.cr.yp.to https://nacl.cr.yp.to), but picking a standard randomly will not get you them.