4 ms·
What about writing a library that wraps OpenSSL and only implements a couple, strong ciphers/modes? Specifically, AES-256-CBC and RSA 4096? I mean, I've done m
by listrophy 15y ago
What about writing a library that wraps OpenSSL and only implements a couple, strong ciphers/modes? Specifically, AES-256-CBC and RSA 4096?
I mean, I've done my homework: I know enough to not call myself an expert, yet also know enough to avoid every crypto-algorithm like the plague until I've thoroughly investigated it and its "competitors."
- tptacek 15y agoSaying "AES-256-CBC and RSA 4096" isn't nearly enough detail to assess whether you know what you're talking about, and pushing me through a thread to the limit of what I personally know how to break is just going to give you false confidence, because I know less than a lot of people I know. In case this is what you were implying: it is absolutely not the case that the big problem with OpenSSL is that it'll let you use Camellia in ECB or 512 bit ElGamal. The problem is that there are (a) more things you can do terribly wrong with AES-256-CBC than there are things you ar likely to do with wrong with, say, C memory handling, and (b) things you have to do well beyond encrypting soundly with AES-256-CBC to make your system work as a whole.
- listrophy 15y agoAs with all things security, nothing is absolute... your reply is well received. Thank you.