4 ms·
You're trying to tell us that software from 2019 isn't new? The majority of the software that I use on a daily basis is minimum a decade old, and I don't think
by z0r 5y ago
You're trying to tell us that software from 2019 isn't new? The majority of the software that I use on a daily basis is minimum a decade old, and I don't think I'm alone.
- CiPHPerCoder 5y agoIt isn't brand new, no.
- johnisgood 5y agoYeah, and it is supposedly a software related to cryptography. Has it been audited at least? They are promoting it so much, but GnuPG has been around for a while now and loads of people have used it. What about Age? I feel more comfortable with GnuPG.
- CiPHPerCoder 5y agoWhat is your bar for "audited"? I've reviewed both the design and implementation for age in the past and only found nitpicky things to improve (mostly related to HKDF). I can take a fresh look and make a pretty PDF on paragonie.com if you care so much.
- johnisgood 5y agoI am sure audits could help Age either way. :) I am just saying that it is still fresh as opposed to GnuPG. This is what people typically call "battle-tested", when the software has been used by a zillion of people for some time. Of course I cannot speak about Age much, this is the first time I heard about it.
- tptacek 5y agoGnuPG had been battle tested for almost two decades before Efail was discovered and disclosed.
- johnisgood 5y agoYeah, but does this help Age?
- tptacek 5y agoOnly to the extent that it shows you can't simply compare the vintage of two systems and declare the older one safer by dint of battle-testing.
- johnisgood 5y agoI am not saying it is safer because it is older, but it sure has been under more scrutiny than Age. That said, Age might be safer regardless.
- akerl_ 5y agoCan you describe the upside of this “more scrutiny”, since per the above it doesn’t seem to have made the codebase safer?