7 ms·
Libsodium: A modern, portable, easy to use crypto library
- _ocro 3y ago[flagged]
- vishnumohandas 3y agoThis is arguably the safest library you can use if you are adopting crypto. The documentation is a delight to read and the abstractions make it difficult to make mistakes. Fun fact, the author (Frank Denis) is an incredibly talented photographer[1]. [1]: https://prettysimpleimages.format.com/ https://prettysimpleimages.format.com/
- _ocro 3y ago[flagged]
- ignoramous 3y ago> This is arguably the safest library you can use if you are adopting crypto. The documentation is a delight to read and the abstractions make it difficult to make mistakes. Its Daniel J Bernstein's world, we merely live in it: - http://www.metzdowd.com/pipermail/cryptography/2016-March/028824.html http://www.metzdowd.com/pipermail/cryptography/2016-March/02... - https://cr.yp.to/highspeed/naclcrypto-20090310.pdf https://cr.yp.to/highspeed/naclcrypto-20090310.pdf
- twsted 3y agoVery interesting, thanks for the links.
- sillysaurusx 3y agoWhat a fantastic essay. I’ve stolen it and submitted it as a new story. Poor Colin, always having to live in the shadow of the one critical Tarsnap failure due to a missing ++. By the way, what does “oth” stand for in your profile? You’ve made the most extensive tagged list or HN users I’ve ever seen. Thanks for that.
- Philpax 3y ago"other"?
- jszymborski 3y agoOh it's Peter Gutmann of the Gutmann method! https://en.wikipedia.org/wiki/Gutmann_method https://en.wikipedia.org/wiki/Gutmann_method
- radicalbyte 3y agoFantastic documentation, very easy to use and it has bindings for pretty much every language you can imagine.
- rurban 3y agoNot really. Its memsetter is unsafe still
- hot_gril 3y agoYep, I used a js wrapper around it one time in a pet project involving e2ee. The creator(s) of libsodium seem to understand the importance of security features being easy to use and hard to misuse, which sounds obvious but is often not prioritized enough.
- aborsy 3y agoThis guy is amazing. He might be the user jedisct1 above. He has implemented a WIDE range of crypto! At the same time, he a professional photographer!
- _ocro 3y ago[flagged]
- _ocro 3y ago[dead]
- _ocro 3y ago[flagged]
- _ocro 3y ago[dead]
- _ocro 3y ago[flagged]
- birracerveza 3y agoYou ok buddy?
- actualwitch 3y agoSomeone's account got stolen. No surprise with no mfa.
- deleted 3y ago[deleted]
- _ocro 3y ago[dead]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- _ocro 3y ago[flagged]
- brucethemoose2 3y agoNot to be confused with Sodium, the Minecraft rendering engine rewrite: https://modrinth.com/mod/sodium https://modrinth.com/mod/sodium
- _ocro 3y ago[flagged]
- lcrz 3y agoLibsodium is an amazing crypto library. At my previous job, we used libsodium as the basis for all our crypto on web, iOS and android. This after a myriad of subtle problems and inconsistencies using multiple libraries for RSA/AES. Libsodium is pretty opinionated, which is good. The only thing that actually came close in dev experience was google’s ~~Think~~ Tink library, but that isn’t mature on web and probably never will be. It’s also hella fast. Edit: corrected library name
- forty 3y agoThe library is Google Tink (just in case someone wants to look it up)
- greenicon 3y agoI can fully recommend Tink, especially when libsodium isn’t available. Although its documentation isn’t very good, it‘s build to be hard to misuse. You still need some cryptographic knowledge though, as it isn’t that opinionated as libsodium.
- hellooutter 3y ago[dead]
- commandersaki 3y agoTink is pretty yuck, needs a JSON parser just to load keys.
- loup-vaillant 3y agoIf I recall correctly Libsodium has an official web site: https://doc.libsodium.org/ https://doc.libsodium.org/ No need to link to the repo aggregator.
- FrostKiwi 3y ago> repo aggregator Love it. Has a bit of passive aggressive pizzazz.
- ggm 3y agoGoogle search suggests there are already implemations of QUIC, TLS and SSH which use libsodium. Given the dependency of Web and login on both, I like this.
- Sjoerd 3y agoWhen doing symmetric encryption you usually need a nonce or IV, which is also sent to the other party along with the ciphertext and authentication tag. Why does the API for libsodium allow you to specify your own nonce and keeps it separate from the ciphertext? The function crypto_secretbox_easy includes the authentication tag in the ciphertext, but you still have to provide the nonce yourself and it is not included in the ciphertext. Wouldn't it be easier still if the nonce was generated within this function and also added to the ciphertext?
- tux3 3y agoThat would probably be good for the overwhelming majority of users. More rarely, you want to save space/reduce overhead by using a deterministic IV scheme. Either all 0 because you picked a random key and you _really_ care about space saving, or you're very very sure you can safely count IVs (0, 1, 2, ..) without ever reusing a single one. In those rare cases you don't want to transmit the IV, you just know what the value is supposed to be on both sides. More complexity and danger, but a small percentage of users get to save a few bytes.
- lcrz 3y agoI agree. If you look at the Swift version of the library, it will generate and prepend the nonce for you automatically (if you use the right overloaded method). It will also strip it and use it during decryption. My guess is they wanted to maintain compatibility with NaCl.
- conradludgate 3y agoThe docs have a page on encrypting multiple messages[0]. In it they use a single random IV and then increment it for each message. Under this scheme you only need to transmit or negotiate the IV once. If you use something like TLS, The key exchange is expanded to produce an IV. Then each record has an incremented number[1] and this number is mixed with the IV to form a unique IV[2] for the message. [0]: https://doc.libsodium.org/secret-key_cryptography/encrypted-messages https://doc.libsodium.org/secret-key_cryptography/encrypted-... [1]: https://www.rfc-editor.org/rfc/rfc8446#section-5.3 https://www.rfc-editor.org/rfc/rfc8446#section-5.3 [2]: https://www.rfc-editor.org/rfc/rfc8446#appendix-E.2 https://www.rfc-editor.org/rfc/rfc8446#appendix-E.2
- Alifatisk 3y agoHow do C (C99) manage and use libraries from the web? Do I just download the header files and use it that way, or is there a package manager for this? In that case do I manage updates by removing the old header file and download the new version?
- hellooutter 3y ago[dead]
- eddtests 3y agoSomeone more experienced at C can jump in and correct me but from my understanding you're correct, you download the files. You could use git to create subrepos for dependencies in a directory in your project, too. When I've asked this question before those were the answers I got.
- Alifatisk 3y agoI saw a project called conan.io, looked interesting. I know Microsoft created vcpkg.io aswell. I’m too used to Ruby and how gems are installed, I think I’m looking for a similar experience in C where you find the lib you want, install it and include it in your code.
- eddtests 3y agoYeah I looked at conan and you can specify git projects to install which is nice. I expect vcpkg to be great for a Windows / Visual Studio setup but I'm on Mac/Linux so haven't really looked. Even with Conan I've not found something as nice as gems/pip/npm for ease of use and it's one of the reasons I end up looking at Rust - because cargo is so familiar to me from a Python background. Edit: I saw a project recently written in C++ and they had subrepos in a `deps/` directory and then linked to those, so it was all manually managed. If I were to make a new project in C++ I think that's how I'd go too.
- arianvanp 3y agoI use Nix as a package manager for my C projects. It works very well and has out of the box support for most C build systems (make, autotools, cmake, meson)
- deleted 3y ago[deleted]
- datadeft 3y agoList of authors is crazy. https://raw.githubusercontent.com/jedisct1/libsodium/master/AUTHORS https://raw.githubusercontent.com/jedisct1/libsodium/master/...
- deterministic 3y agoOr perhaps use a crypto library that is actually formally proven correct: https://project-everest.github.io/ https://project-everest.github.io/
- olabyne 3y agodon't forget https://github.com/jedisct1/libhydrogen https://github.com/jedisct1/libhydrogen for microcontrollers
- jedisct1 3y agoNot just for microcontrollers. If performance is not a priority, but you need something small, simple, and easy to embed, libhydrogen can come in handy. I actually use it more than libsodium.
- loup-vaillant 3y agoThen don’t forget https://monocypher.org https://monocypher.org as well. Bigger than libhydrogen but still small enough for many targets, faster across the board, and compatible with libsodium. If you can spare a couple more KB of flash in your microcontroller, you can get very good performance on the device and use libsodium on the server to scale like crazy. It also doesn’t hurt that there is basically 1 header and 1 source file (2 of each with the options), which you can trivially copy & paste into your project.
- conradludgate 3y agoLibsodium is a great library, but as I'm in the Rust ecosystem and since we all must Rewrite it in Rust I am very interested in the RustCrypto project[0]. I previously used sodiumoxide[1] libsodium bindings in my projects but they are in maintenance only mode and wouldn't accept patches to build on other platforms (we had raspberry pi users complaining they couldn't build our software because of sodiumoxide). Maintaining cross platform C libraries which use assembly primitives is pretty tricky. The ring[2] library - which is used by rustls (a better tls library for rust) - is notoriously annoying to cross compile because of its use of C and assembly. [0]: https://github.com/rustcrypto https://github.com/rustcrypto [1]: https://github.com/sodiumoxide/sodiumoxide https://github.com/sodiumoxide/sodiumoxide [2]: https://github.com/briansmith/ring https://github.com/briansmith/ring
- commandersaki 3y agoThe `dryoc' crate gives tit for tat compatibility with libsodium using native rust primitives.
- loup-vaillant 3y agoTo be honest maintaining bindings for a whole library is kind of a bear, so many people who do this tend to stick to the most used high-level interfaces. Even for my library, which has fewer than 50 functions. If you use a sufficiently narrow subset, my advice would be to do your bindings yourself. It’s thankless work, but it’s work you control, and you’ll be able to tailor your side to your liking.
- aborsy 3y agoWhat command line tool do you recommend for file encryption and signatures by the end user?
- loup-vaillant 3y agoRight now the most established are Age and Signify, respectively. I have no experience with them, but they’re reputable, and what little I saw was good.
- jedisct1 3y agoLibsodium has been around for a while, so probably the reason it was posted is that version 1.0.19 was just released: https://github.com/jedisct1/libsodium/releases/tag/1.0.19-RELEASE https://github.com/jedisct1/libsodium/releases/tag/1.0.19-RE... Updated NuGet and Swift packages are going to be uploaded soon. AEGIS-128X and 256X are not there yet, but if you need them, they are available in libaegis: https://github.com/jedisct1/libaegis https://github.com/jedisct1/libaegis All the code from libaegis will eventually be merged into libsodium, including the incremental update API which is especially useful for TLS.
- fatfingerd 3y agoWhen I first learned of NaCL/libsodium I was very interested in a new API but.. It seems to me like if you go with anything along these lines you have very little chance of ever supporting hardware protected keys (smartcards, hsms, etc) and, quite frankly, I'm not sure any data should be stored on a normal computer or mobile phone that you wouldn't publish in a blog, so having a software key is madness, IMO.
- Zamicol 3y agoThere's also https://monocypher.org https://monocypher.org