4 ms·
Obviously you're being somewhat facetious. If you're good/confident enough to write your own crypto, go seems fine as it's open source so you can inspect it. I
by greendata 13y ago
Obviously you're being somewhat facetious. If you're good/confident enough to write your own crypto, go seems fine as it's open source so you can inspect it. I don't trust myself to write my own crypt for important things, so obviously I would not use Golang for that and I would pause before using the Golang crypto module, but that's probably a bit paranoid. In general, I would probably use Golang on projects. I use Angular.s and Python and those have been funded in ways by Google.
Things like Google App Engine/Data store are an issue b/c your backend is Google's backend...fundamentally the same issue Gmail faces. If the NSA/FBI/DEA/TSA mistakenly fingers one of my customers as a drug dealer or "terrorist" or thinks they are associated with a drug dealer/whistleblower/"terrorist", google will hand over all my apps data.
- jaekwon 13y agoGood analysis, I largely agree. Then again, you hear about Microsoft or Sun/Oracle passing notes to the NSA about insecurities in the OS or JVM so that they can go about their stealthy ways. I wouldn't be surprised if the same happened with Go. But good point, it's open source. There is also an issue with Go dependencies that may make it easier to introduce vulnerabilities. The solutions are discussed here: http://kylelemons.net/blog/2012/04/22-rx-for-go-headaches.article http://kylelemons.net/blog/2012/04/22-rx-for-go-headaches.ar...
- greendata 13y agoGood point about the dependencies. If it was something that someone's life depended on, especially mine, I'd do the encryption operations in a vetted C/C++ library due to possible dependency issue in GOLANG. I just don't know enough about GO or even encryption for that matter.