4 ms·
On this topic, what is the header-only, no-dependencies, portable, bsd licensed, simple C api, github project we should be using instead ?
by bartwe 5y ago
On this topic, what is the header-only, no-dependencies, portable, bsd licensed, simple C api, github project we should be using instead ?
- jedisct1 5y agoLibhydrogen ?
- rdpintqogeogsaa 5y agoMonocypher[0], unironically. Though it's not header-only (it's a single C file and a separate header), but it's easy enough to merge the two. It even beats your licensing requirements (CC-0 or BSD 2-clause dual-license). [0] https://monocypher.org/ https://monocypher.org/
- FabHK 5y agoThat's written by Loup Vaillant who wrote "Roll your own Crypto", basically [1]. Is the consensus that it is production quality? [1] https://loup-vaillant.fr/articles/rolling-your-own-crypto https://loup-vaillant.fr/articles/rolling-your-own-crypto , discussed here: https://news.ycombinator.com/item?id=13221923 https://news.ycombinator.com/item?id=13221923 and related https://news.ycombinator.com/item?id=14917378 https://news.ycombinator.com/item?id=14917378
- rdpintqogeogsaa 5y agoThere's been an audit[0], at least. [0] https://monocypher.org/quality-assurance/audit https://monocypher.org/quality-assurance/audit No high or critical issues were found. The issues that were found were addressed in a timely manner.
- psanford 5y agohttps://www.reddit.com/r/programming/comments/5iv1ti/rolling_your_own_crypto/dbbmwwo/ https://www.reddit.com/r/programming/comments/5iv1ti/rolling...
- opheliate 5y agoIMO it's really unfortunate that Monocypher doesn't implement a high-level CSPRNG API. I appreciate that it goes against the design goal of being entirely dependency-free, but getting random number generation wrong is such an easy foot-gun in my view, and it's already my least favourite part of libsodium (its most obvious "competitor") that the AEAD constructs don't generate a random nonce for you. Edit: Also, not sure why the author chose to use Argon2i over Argon2id as the PBKDF for Monocypher, my perception was that the id variant should be used unless you have a reason not to. Would be interested to hear other opinions on this.