3 ms·
> > Even giving the user a choice of ciphers to use is a recipe for disaster. > How so? I'm still learning this stuff, so I'm genuinely curious. https://parag
by CiPHPerCoder 6y ago
> > Even giving the user a choice of ciphers to use is a recipe for disaster.
> How so? I'm still learning this stuff, so I'm genuinely curious.
https://paragonie.com/blog/2019/10/against-agility-in-cryptography-protocols https://paragonie.com/blog/2019/10/against-agility-in-crypto... :)
- user5994461 6y agoI really hope you're planning some agility in PASETO otherwise it's de-facto s* protocol that will have to be thrown away within a few years upon the first cryptographic weakness, breaking all applications that dared to adopt it. Fact is, ciphers and protocols evolve over time. In the real world of client-servers (often many clients and many servers), it's not possible to magically upgrade all systems at once to exclusively accept a single same cipher. There's got to be a way to phase-in ciphers gradually across systems and phase-off. Agility is simply a real world constraint to be able to operate software in the real world.
- griffinmb 6y agoIt’s versioned, which is an improvement on “agility”
- CiPHPerCoder 6y ago> I really hope you're planning some agility in PASETO otherwise it's de-facto s* protocol that will have to be thrown away within a few years upon the first cryptographic weakness, breaking all applications that dared to adopt it. Instead of cipher agility, PASETO uses versioned protocols. My DEFCON Crypto & Privacy Village talk (slides and YouTube video at https://paseto.io https://paseto.io for the curious) covered this distinction in detail.