4 ms·
> And besides, how will you update our map that says that protocol "age" 1 uses rsa, "age" 2 uses ed25519? With protocol versions, which don't require a regist
by FiloSottile 6y ago
> And besides, how will you update our map that says that protocol "age" 1 uses rsa, "age" 2 uses ed25519?
With protocol versions, which don't require a registry for the primitives. Like, there is no number that means RSA and no number that means Ed25519, there is just age v1 and age v2, and each of them uses only the one specified primitive. If you want to call version numbers registries, sure, but I think you get what I mean.
People bring up "what about AES hardware" a lot, but they also seem to like Wireguard, which also happens to be the fastest VPN option for most deployments. Well, Wireguard just silently went and did what I'm advocating, including only supporting ChaCha20Poly1305.
- Luker88 6y agoSo instead of having "primitive1 = rsa" you have "age1 = rsa". It's the same thing. You are just bumping the protocol version faster, and confusing people because protocol 42 will be just another crypto change, but 43 will be a complete protocol rewrite. Meanwhile each protocol version needs to be standardized and accepted by the whole world. That stuff is not fast
- some_furry 6y agoYour theory doesn't seem to have stopped WireGuard from becoming a successful high-performance VPN protocol/implementation.