3 ms·
(1) and (3), yes. (2) is not about process authentication but about using authenticated encryption that detects tampering. More broadly, there needs to be a th
by FiloSottile 4y ago
(1) and (3), yes. (2) is not about process authentication but about using authenticated encryption that detects tampering.
More broadly, there needs to be a threat model that states what your attacker is capable of.
Even more broadly, I get the impression you’re not an experienced cryptography engineer and you didn’t work with one. Learning is great, but this is not presented with any warnings, which is irresponsible.
- aegistudio 4y agoYou are right. I don't come with cryptography background and haven't consider the attack model carefully. I will warn the users about the current status and strive to design it to confront potential attacks.
- shiittile 4y ago[flagged]
- aae42 4y agoJust wanted to note that while the posts were terse, I can't say I would consider them arrogant or non constructive. If I were the author of Enigma I'd be thrilled to get feedback from Filippo. Also, it seems immediately constructive just from the reply you replied to. That said, I kind of have to agree, "you don't know what you don't know" often holds true in the matter of cryptography, and failure tends to be pretty damaging to the user. Actually, not posting a disclaimer when trying to solve a difficult problem as an amateur might be what should be considered arrogant.