3 ms·
Hey! I'm MeshBird's author. Feel free to ask a questions.
by miovoid 10y ago
Hey! I'm MeshBird's author. Feel free to ask a questions.
- chetanahuja 10y ago@rickette posted this: "Just took a quick look at the crypto implementation. It uses AES-256 in CBC mode but..... without an authentication tag (HMAC)." Any response?
- miovoid 10y agoGood point. We are going to implement AES-GCM encryption based data transfer. Why AES-GCM to solve HMAC missing? Because Go have low-level asm optimisations. This is open way to full utilization of 10G/40G networks.
- wtbob 10y agoSeriously, I'd advise that you implement an HMAC today, and implement GCM tomorrow — using raw CTR mode really is that dangerous. And make sure that you never ever ever reuse IVs, ever. This sort of thing is incredibly dangerous. Props to you for coming up with a great UX, but crypto is very, very difficult to get right.
- qrpike 10y agoKeep up the good work! Much appreciated