3 ms·
Libsodium (a fork of NaCl) is preferable to NaCl. JS: https://www.npmjs.com/package/sodium-plus https://www.npmjs.com/package/sodium-plus (I wrote this one.)
by CiPHPerCoder 7y ago
Libsodium (a fork of NaCl) is preferable to NaCl.
JS: https://www.npmjs.com/package/sodium-plus https://www.npmjs.com/package/sodium-plus (I wrote this one.)
Lisp: https://github.com/orthecreedence/cl-sodium https://github.com/orthecreedence/cl-sodium
Java (Android): https://github.com/terl/lazysodium-android https://github.com/terl/lazysodium-android
Other bindings: https://libsodium.gitbook.io/doc/bindings_for_other_languages https://libsodium.gitbook.io/doc/bindings_for_other_language...
- lawl 7y ago> Libsodium (a fork of NaCl) is preferable to NaCl. Can you elaborate on this? Quickly looking over your libsodium based sodium-plus it doesn't seem like it has been audited. (I know libsodium itself had an audit) Where as for example tweetnacl-js [0] has been audited. That's not meant to take a dump on your project, but I just don't understand why it is better, or preferable. [0]: https://github.com/dchest/tweetnacl-js#audits https://github.com/dchest/tweetnacl-js#audits
- CiPHPerCoder 7y agoNaCl is djb abandonware. Libsodium is actively maintained. Libsodium offers Argon2 password hashing and key stretching, XChaCha20-Poly1305 AEAD constructions, BLAKE2b generic hashing, SipHash-2-4 for collision-resistant hash tables, etc. Most people who say "use NaCl" really mean "use NaCl/libsodium". Regarding my project: sodium-plus will wrap sodium-native (a thin Node wrapper to libsodium proper, which has been audited) if it is installed. To date, libsodium.js has not. Therefore, if you care about public code audits, you can use audited libsodium with sodium-plus just by installing sodium-native alongside it.