3 ms·
The v1.0.0 was published the day a bug was fixed and yet the first sentence of this post is "Monocypher is ready for production". Sure, OpenSSL has bugfixes on
by conradk 9y ago
The v1.0.0 was published the day a bug was fixed and yet the first sentence of this post is "Monocypher is ready for production". Sure, OpenSSL has bugfixes on regular basis as well, but I believe that further fragmenting the crypto ecosystem with a new library and little commercial support to properly back it and pay for security audits is risky.
- baby 9y agoIt's risky but sometimes it's the only way. To be fair the code size is relatively small so it should be easier to audit than other products. My guess is that his blog post is also some motivation to get new pair of eyes on the library. If there's any fund for that, I'd be happy to look at it ;)
- loup-vaillant 9y ago> The v1.0.0 was published the day a bug was fixed and yet the first sentence of this post is "Monocypher is ready for production". You have to consider the nature of the bug, as well as the fix. The bug was an Undefined Behaviour that had no effect on the binaries I could generate. The fix was 10 characters. Running the automated test suite took longer than fixing the bug. If there were reasons to delay 1.0, this bug was not it. > I believe that further fragmenting the crypto ecosystem with a new library and little commercial support to properly back it and pay for security audits is risky. I agree fragmentation is a problem. I just couldn't satisfy myself with existing alternatives. As for support, I designed Monocypher specifically to need very little of it. Ideally, the only notable changes from now on will be about the manual and the test suite.