3 ms·
> Isn't it safer to learn and understand how to use, say, AES algorithm No. AES by itself is just a function that provides symmetric encryption of one fixed s
by floatboth 7y ago
> Isn't it safer to learn and understand how to use, say, AES algorithm
No.
AES by itself is just a function that provides symmetric encryption of one fixed size block. You can't do anything with "just AES". Bad libraries will throw a choice of block cipher modes at you, and tell you to pick CBC or CTR. Then you won't even realize that you have no integrity checking at all on these messages. If you do, you'll maybe add an HMAC, and end up with encrypt-then-MAC or MAC-then-encrypt and ughhhh.
Just use a high level library that provides idiot-proof APIs with descriptive names like "secret box".
> If I am to verify if any of those ports is a proper one probably I would have to really become a crypto expert.
These things aren't ports!!! They're simple FFI bindings. Take a quick look at the code (heck, the readmes say things like "Java Native Access" already, this should ring a bell).