4 ms·
> I couldn’t find anything that fit the bill, so I did exactly what you’re not supposed to do and rolled my own: Enchive. Someone correct me if I'm wrong, but
by problems 10y ago
> I couldn’t find anything that fit the bill, so I did exactly what you’re not supposed to do and rolled my own: Enchive.
Someone correct me if I'm wrong, but I think the main thing you're "not supposed to do" is create or implement your own primitives.
If you have a decent understanding of the software engineering and cryptographic implications around them - especially if you're using a high level library like libsodium, implementing high quality algorithms into your own applications is fairly well supported.
Of course, before anyone puts much faith in it they probably want some reputation at stake at the very least, but the primitives you've gone with are some of the hardest to screw up with the least weird side effects around.
- simias 10y agoIf you look at the code on github he doesn't appear to have implemented the algos from scratch, rather he reused public domain code. It's still very much possible to make a mistake while wiring it all together though, especially in C. EDIT: actually the curve25519-donna code is from Google and appears to be BSD-like. The chacha and sha256 implementations are public domain however.
- problems 10y agoYeah, what's exactly what I was saying. He's using existing high quality algorithm implementations and integrating them into his new tool. The only custom part is how exactly he uses them in his code. While it's totally possible to screw that up, it's also not really the majorly discouraged part.
- Anderkent 10y agoIt's not just primitives that you're not supposed to reimplement. Wiring primitives together to build a secure full-featured system is very error prone. That's exactly why libsodium is recommended so often - it does most of the wiring for you.