24 ms·
Ed25519-CLI – command-line interface for the Ed25519 signature system (2024)
- alexjurkiewicz 9mo ago(2024) My favourite part of these tools is the zany use of numbered file descriptors. `keypair` outputs the public key on fd 5 and secret key on fd 9. But signing reads the secret key on fd 8, while verification reads the public key on fd 4! Why aren't they the same?? I have to read the manpage every time.
- Retr0id 9mo agoI'm curious, what do you actually use it for? I'd have otherwise guessed that this tool mainly exists just to test lib25519. Personally I'd only ever want a library, or some higher-level tool. A CLI tool that just does raw signing feels like a weird (and footgun-shaped) middle ground.
- XorNot 9mo agoIt's why no one has succeeded in replacing GPG: you need a lot of systems to work in order to have an actual viable one, the ability to spit out signatures from keys is required but not sufficient.
- adastra22 9mo agoGPG is pervasive for the same reason git is pervasive: network effects. There are plenty of better alternatives.
- XorNot 9mo agoSuch as? I need an alternative which supports commutative trust relationships of some sort which are revocable.
- C4K3 9mo agoKeybase or any of the tools inspired by keybase (foks.pub etc)
- adastra22 9mo agoIsn’t keybase to GPG what github is to git?
- adastra22 9mo agoYou (knowingly?) picked the one counter example, lol. Web of trust is the one application of PGP/GPG for which there isn’t a product ready replacement tool to point towards. GPG is built around web of trust, but this is generally believed to have been a very, very bad idea and the source of innumerable security problems for nearly every application that has tried to make use of it. The GPG replacements I would point to are purpose-built for specific domains and eschew web of trust: https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ That said, you might find what you are looking for in the Rebooting Web of Trust project, and the various decentralized identity (DID) implementations that have come out of it: https://www.weboftrust.info/ https://www.weboftrust.info/
- XorNot 9mo agoNo I picked the case I'm dealing with most commonly: which is establishing trust. X509 certs will also do this. I have numerous criticisms of the GPG system but it's not a solution to just not implement any solution at all: I.e. I need revocation lists, I need intermediate keys, I need the ability to establish alternate chains of trust or promote a chain to trusted. Some of this is very hard to do with x509 even or not will supported.
- adastra22 9mo agoTrust meaning who you should do business with? Whose advice you should take? Rather than “trust” you mean something very specific: whether a key was issued by an entity, or attested to from a set of authorities. The “web of trust” model that PGP/GPG supports is not the ideal means of implementing this.
- tptacek 9mo agoThis mostly exists to test lib25519 and ostensibly to build systems with shell scripts (though: few people would do that). It is a weird and footgun-shaped middle ground.
- Fnoord 9mo ago> I'm curious, what do you actually use it for? FTA: > These tools allow lib25519 to be easily used from shell scripts. I've never used ed25519-cli, but not having to use a library is nice for someone who isn't a programmer.
- tptacek 9mo agoThe Venn diagram of "not a programmer" and "can safely use Ed25519" is two non-overlapping circles.
- alexjurkiewicz 9mo agoSimply combine this tool with `openssl enc` and your shell script is as secure as any shell script could be
- kfreds 9mo agoI don't consider myself a programmer and I can use Ed25519 safely. I do however understand computing fairly well.
- Retr0id 9mo agoI consider myself a programmer and ed25519-understander, but the idea of using it directly within a shell script terrifies me.
- PunchyHamster 9mo ago"this app needs me to generate a key and point to it in config" is plenty of overlap
- Retr0id 9mo agoIf you just want a raw ed25519 private key then `head -c32 /dev/urandom` does the job. But usually you want a DER/PEM wrapper or similar, which the openssl cli tools handle nicely.
- 9mo ago
- deleted 9mo ago[deleted]
- jedahan 9mo agoI was wondering the same thing. My best guess is that is to guard against operator misuse. Like usb-a only plugging in one way. Anything that is secret will never accidentally print to stdout. String interpolation in bash with `—option $empty` might be safer than `8<$empty`. Have to explore more but yeah, this is a new pattern for me as well.
- yellowapple 9mo agoAnother possible factor driving the decision to use numbered file descriptors: the logic to validate that a file exists (or can exist) at a given path, is readable/writable, etc. gets punted to the shell instead of being something the program itself has to worry about.
- gnull 9mo agoThose descriptors like 5 could be mapped to anything, including descriptor 1, stdout.
- chuckadams 9mo agoWhat a strange convention. I'm partial to minisign, which works on plain old files.
- tptacek 9mo agoThis little CLI is not meaningfully an alternative for signify/minify. Here's a good piece on signify from its author (who also comments here): https://www.openbsd.org/papers/bsdcan-signify.html https://www.openbsd.org/papers/bsdcan-signify.html
- pamcake 9mo ago[dead]
- gnull 9mo agoThat's such a user-hostile design decision. I can't fathom what justifies it (other than kinky taste). Makes your commands unreadable without a manual, leaves a lot of room for errors that are quietly ignored. And forces you into using a shell that comes with its own set of gotchas, bash is not known to be a particularly good tool for security. And to those who stay this adds flexibility: it doesn't. Those file descriptors are available under/dev/fd on linux, with named options you can do --pk /dev/fd/5. Or make a named pipe.
- PunchyHamster 9mo agoit being option can be nice if you don't want your keys touching disk and need to pass it over to other apps. it being default is insanity
- minitech 9mo ago> Those file descriptors are available under/dev/fd on linux, with named options you can do --pk /dev/fd/5. If you have a procfs mounted at /proc and the open syscall to use on it, sure (and even then, it’s wasteful and adds unnecessary failure paths). Even argument parsing is yet more code to audit. I think the design is pretty good as-is.
- gnull 9mo agoIt's 2025, dude. You can't be seriously telling me how difficult it is to parse arguments. It may be difficult in C, but then we're down another sick rabbit hole of justifying bad interface with bad language choice. One open syscall in addition to dozens already made before your main function is started will have no observable effect whatsoever.
- minitech 9mo agoThe context is what’s essentially a shell-accessible library for a minimal set of cryptographic primitives. It’s very reasonable to want it to be as lightweight, portable, and easy to audit as possible, and to want it to run in environments where (continuing on Linux for example) the open syscall to /dev/fd/n -> /proc/self/fd/n will not succeed for whatever reason, e.g. a restrictive sandbox. Not involving argument parsing simplifies the interface regardless of how easy the implementation is, and the cost is just having to look up a digit in a manual that I certainly hope anyone doing raw ed25519 in shell is reading anyway.
- pseudohadamard 9mo agoIt's djb's web site so it's a djb design. With great genius comes great different thinking.
- alfiedotwtf 9mo agoI’m guessing it’s to support the test framework it’s built with?
- PunchyHamster 9mo agosupport is fine. Being default is crazy
- why-o-why 9mo agoWhy not zoidbe... I mean, why not open ssh? It's literally a CLI that does every crypto operation with every primitive (except some PQC)?
- tptacek 9mo agoIf you mean the OpenSSL CLI, it's hard to think of a more footgun-y cryptographic tool than the one that: * defaults to unauthenticated encryption * buries its one authenticated mode * requires explicit command-line nonces * defaults to an MD5 KDF You could probably keep going for another 10 bullets. Never use the OpenSSL CLI for anything other than TLS stuff.
- quotemstr 9mo agoYeah, the OpenSSL CLI sucks. So what's to be done? Sure, we can build a 25519-specific tool with a less footgun-y interface. Fine, whatever, for that one use case. Or we can build an alternative OpenSSL CLI that explodes OpenSSL and its numerous useful features in a general way and helps fix lots of use cases.
- tptacek 9mo agoNothing is to be done. Just don't use the OpenSSL CLI. It's a deeply cursed concept for a tool!
- esseph 9mo ago> feels like a weird (and footgun-shaped) middle ground. hmm > It is a weird and footgun-shaped middle ground. Oh? HMMMMM :|
- mrbluecoat 9mo agoSounds like the perfect place to embed credential stealing malware. Good thing they publish their code on an independent third-party public code sharing platform. Oh wait...
- perching_aix 9mo agoShort of suspecting a malicious tarball, I really can't think of a reason why "publish[ing] their code on an independent third-party public code sharing platform" would be a selling point. You're getting the source code straight from the horse's mouth this way.
- WiSaGaN 9mo agoI can't find the source. Anyone can point to it?
- minitech 9mo agoThe Download link in the header (https://lib25519.cr.yp.to/download.html https://lib25519.cr.yp.to/download.html).
- PunchyHamster 9mo ago> It writes the public key to file descriptor 5, and then writes the secret key to file descriptor 9. Is the project trying to compete with GPG for worst interface ? Magic numbers BAD, especially in something that will mostly be used in scripts
- deleted 9mo ago[deleted]