3 ms·
This is a bit similar to roll your own crypto conversation. It is fun, and a great way to learn. And once done, you should do well to never deploy your own cryp
by rixrax 3y ago
This is a bit similar to roll your own crypto conversation. It is fun, and a great way to learn. And once done, you should do well to never deploy your own crypto in any real life application.
Friends don't let (or shouldn't at least) friends roll their own protocol over UDP either (or IP; I mean why not?). There are very few apps that have such an explicit requirements that they can't do away with TLS over any number (==2) of existing, and well known transport protocols (e.g. TCP, maybe QUIC). For presentation layer, instead of implementing their own spec, most should probably stick to Protobuf[0] (or some of it's derivatives[1]), and encode the application data into JSON.
Check. Protocol design done.
[0] https://protobuf.dev https://protobuf.dev
[1] https://capnproto.org https://capnproto.org
- em-bee 3y agoi don't quite agree because there are legitimate uses for UDP, but there are no legitimate uses for hand rolled crypto (except learning). also the issues with UDP mentioned in the article can easily be mitigated, which is not at all true for issues with hand rolled crypto. and there is one important use for UDP that is not well served with TCP or QUIC, which is tunneling. tunneling TCP over TCP does not work very well. also, the feature of mosh to keep a connection alive over network changes may not be easy to implement over TCP, i am not sure.