6 ms·
Where is the author rolling their own crypto? They’re simply importing Node’s standard crypto library and using AES, a CSPRNG, and PBKDF2. Whether the usage is
by e79 6y ago
Where is the author rolling their own crypto? They’re simply importing Node’s standard crypto library and using AES, a CSPRNG, and PBKDF2. Whether the usage is secure is another question, but I wouldn’t say this counts as “rolling your own crypto.”
- tialaramex 6y agoThe code has changed substantially since this was first posted, based on feedback in these threads. So it's bad now than it was when some of these comments were written. That's definitely a good thing in terms of the quality of the code now by the way, I don't see any changes that make it worse and many make it better. But it does mean comments may not refer to the source you looked at.
- whatl3y 6y agoYes thank you for your initial comments, made some of your changes and published a new major version now using PBKDF2. Definitely am learning a lot along the way :)
- tialaramex 6y ago> So it's bad now than it was when some of these comments were written. Too late to edit this after having slept but I think the word I wanted here was "better" not "bad" ?
- forty 6y agoIn rolling your own crypto, crypto doesn't mean cryptography but cryptosystem. The author is not rolling their own cryptography (which is good) but they are clearly using a home made cryptosystem (and not PGP, TLS, or libsodium for example). For example they forgot authenticating their encryption, and the with "password extension" getFilledSecret is more than doubvious. Rule of thumb: if you are using cryptographic primitives directly (such as AES) you are rolling out your own crypto.