3 ms·
It's open source. If you are capable of making such decisions on encryption with founded confidence you can also vendor the library and adapt it. The reality i
by Ajef 5y ago
It's open source. If you are capable of making such decisions on encryption with founded confidence you can also vendor the library and adapt it.
The reality is most developers (almost every developer I know) won't spend particularly much time on deciding settings for encryption - and honestly if they spent 10x the amount they did doing research they would still only base their opinions on things they find online like blog posts (not mathematics or government whitepapers).
I don't believe the approach is bad. It doesn't take the ability away from you to choose. It just adds a hurdle (vendoring the library), which imo stops a lot of bad decisions from overconfident developers.
[edit]: typo