5 ms·
This might be a better starting point: https://paragonie.com/blog/2017/06/libsodium-quick-reference-quick-comparison-similar-functions-and-which-one-use https:/
by CiPHPerCoder 7y ago
This might be a better starting point: https://paragonie.com/blog/2017/06/libsodium-quick-reference-quick-comparison-similar-functions-and-which-one-use https://paragonie.com/blog/2017/06/libsodium-quick-reference...
- skrebbel 7y agoWow, your site is a goldmine! Really loving how you make this subject matter accessible for average nerds like me.
- CiPHPerCoder 7y agoThanks! I wish I were a little better at SEO so average nerds would have an easy time finding it.
- skrebbel 7y agoI just read the article a second time and I really like it. This is precisely the starting point that I was craving for and if I had known about it I might not have written this rant :-) My only SEO advice is patience. Your articles are great, people will link to it increasingly often. That said, why the sole PHP focus? The starting point you just linked to is pretty much independent from PHP, and there's libsodium bindings in plenty languages. If your goal is simply to make good crypto easier to do for "normal" developers then the PHP association may do more harm than good (particularly because PHP is not very hip right now)
- CiPHPerCoder 7y agoI'm mostly to blame for PHP adopting libsodium in version 7.2. Focusing on PHP was pretty on-brand at the time that was written. I'm going to need to update it (Argon2id is now the default), so I might generalize the code (or make a tab system to switch between examples).
- tzs 7y agoIf I write something that uses libsodium, am I violating the near universal "don't roll your own crypto" admonishment, or does libsodium sufficiently hide all the scary dangerous cryptographic stuff so that mere mortals can safely use it?
- CiPHPerCoder 7y agoTL;DR - you're mostly avoiding the admonishment by using libsodium There are still some dangerous things you can do (e.g. mismanage keys, reuse nonces). I wrote a library called Halite for PHP developers that wraps libsodium and makes it even harder to misuse. My philosophy was, "You shouldn't even need to know what a nonce is to use it securely." https://github.com/paragonie/halite https://github.com/paragonie/halite From elsewhere in the thread, PyNaCl takes a similar approach. So how dangerous "just using libsodium" is, with respect to the "don't roll your own crypto" guidance, depends a little bit on which binding you're using. Also, a lot of tasks might require a specific protocol (PAKEs, VPN protocols, searchable encryption, etc.) that libsodium isn't suitable for.
- tabletopneedle 7y agoYes. However, it never hurts to test your code. Assuming you're a C-programmer, read the libsodium docs first. https://download.libsodium.org/doc/public-key_cryptography/sealed_boxes https://download.libsodium.org/doc/public-key_cryptography/s... If you're using higher level language, use a library that provides bindings for it https://download.libsodium.org/doc/bindings_for_other_languages https://download.libsodium.org/doc/bindings_for_other_langua... By using libsodium, you're not rolling your own crypto. Rolling your own crypto would mean -trying to find new one way functions for public key crypto -trying to implement RSA from textbook -trying to implement RSA-OAEP from papers, RFCs, books etc. Using a library is not anywhere near those. There are other ways to fail cryptography too, from not doing public key authentication, to storing private keys in insecure places. So it's highly recommended you take time to read a book on the topic. The best modern book currently availalbe is https://www.amazon.com/Serious-Cryptography-Practical-Introduction-Encryption/dp/1593278268 https://www.amazon.com/Serious-Cryptography-Practical-Introd...
- 7y ago