4 ms·
Go is absolutely committed to the cryptography standard library. What's happening is that we're deprecating legacy protocols and APIs to invest resources on pac
by FiloSottile 3y ago
Go is absolutely committed to the cryptography standard library. What's happening is that we're deprecating legacy protocols and APIs to invest resources on packages that better align with the Cryptography Principles [0].
In particular, crypto/elliptic was an unfortunate API that has been deprecated in favor of the new crypto/ecdh. Most applications can migrate (on their own time, as we don't break backwards compatibility even for deprecated packages) and get better security and performance. (A very small portion of applications might need lower level applications, in which case they can use third party modules based on the stdlib internals, like filippo.io/nistec.) You can read more on my Go 1.20 [1] and Go 1.21 [2] posts.
[0]: https://golang.org/design/cryptography-principles https://golang.org/design/cryptography-principles
[1]: https://words.filippo.io/dispatches/go-1-20-cryptography/ https://words.filippo.io/dispatches/go-1-20-cryptography/
[2]: https://words.filippo.io/dispatches/go-1-21-plan/ https://words.filippo.io/dispatches/go-1-21-plan/