4 ms·
While I agree with your second paragraph, I don't think you need it to justify the position that crypto.secret_box.encrypt is almost always better to use
by throwawaymath 8y ago
While I agree with your second paragraph, I don't think you need it to justify the position that
crypto.secret_box.encrypt
is almost always better to use than a combination of
crypto.primitives.aes.ctr
and
crypto.primitives.hmac.sha256
Aside from the obvious argument that rolling your own cryptography is dangerous, at a more abstract level you just generally don't want to work with raw primitives in most types of software. Specialization isn't just the lifeblood of the economy, it's also the way software productivity works. If your core competency isn't X, why should you be re-implementing X using its raw primitives? You should generally be importing known-good library implementations if possible. Even in adversarial scenarios (like cryptography) this principle remains the same.
Given that I don't really understand the parent commenter's point. You touched on this a little with your example of a Markdown library - as software engineers we use things which are substantially black boxes all the time. It seems strange to me that you'd want to do surgery on the raw primitives of a library instead of updating it to suit your needs. In this case, that means just use a reputable crypto library and update it when there's a reported security vulnerability.
You don't even need to buy into, "Don't roll your own crypto" to lean into this.
- tptacek 8y agoI took the original argument to be "if you use secret_box, you don't even know that you're using Salsa20, so if a cryptanalysis of Salsa20 is published, you might not realize and know to fix that problem". Which is, I think, a silly argument; if someone finds a stack overflow in a Markdown library, I still need the maintainers of that library to tell me about it --- nobody is going to tell me about it directly. I have more information to act on in the secret_box scenario, not less. But I was a little confused by the argument too, so maybe I'm not making that much sense either.