Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
samuel-lucas6
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
ChaCha20-Poly1305-SIV (CCP-SIV)
(github.com)
3 points
by
samuel-lucas6
1y ago
|
0 comments
2.
▲
Ask HN: Has anybody else had payment trouble with the blogging platform Svbtle?
1 points
by
samuel-lucas6
4y ago
|
1 comments
3.
▲
Encrypt-Then-Mac for Committing AEAD (CAEAD) Internet Draft
(samuellucas.com)
1 points
by
samuel-lucas6
4y ago
|
1 comments
4.
▲
by
samuel-lucas6
4y ago
This draft aims to address three problems: 1. It explains how to construct an AEAD scheme by combining an unauthenticated cipher and collision-resistant, hash-based MAC. To my knowledge, this has not been written up before. It's import
5.
▲
Cryptography Guidelines
(github.com)
3 points
by
samuel-lucas6
5y ago
|
0 comments
6.
▲
by
samuel-lucas6
5y ago
That's a fair point. I previously supported -p|--password followed by a password, but I removed that functionality in a later version because strings are immutable in .NET and therefore cannot be zeroed out from memory. Furthermore, I
7.
▲
by
samuel-lucas6
5y ago
I know what it sounds like, but the 'don't roll your own crypto' mantra is completely overused. That advice really applies to creating custom cryptographic algorithms (e.g. a new cipher or hash function) without adequate acad
8.
▲
by
samuel-lucas6
5y ago
Thanks! Yeah, they kind of are.
9.
▲
by
samuel-lucas6
5y ago
Thank you for the kind words. That's why the key exchange in Kryptor is authenticated.
10.
▲
by
samuel-lucas6
5y ago
Yes, you need the recipient's public key, and they need your public key. Your private key is used to perform a key exchange using X25519 ( https://www.kryptor.co.uk/technical-details#private-and-publ... ). Unlike age, th
11.
▲
by
samuel-lucas6
5y ago
Thank you for the feedback! I'll go ahead and reword that.
12.
▲
by
samuel-lucas6
5y ago
That's very true. Asymmetric cryptography is a lot less intuitive, and it's hard to come up with a decent GUI for that kind of functionality. Keybase and keys.pub have probably done the best job.
13.
▲
by
samuel-lucas6
5y ago
Kryptor actually started out as a GUI application, but cross-platform GUI development is a lot harder than CLI development, especially in C#, I didn't want to work on both a GUI and CLI application, and designing a GUI for file signing
14.
▲
by
samuel-lucas6
5y ago
I think incredibly easy is a bit far. Look at how many commands and options there are in total: https://www.gnupg.org/documentation/manpage.html . Beyond that, the website isn't the easiest to navigate, and the gui
15.
▲
by
samuel-lucas6
5y ago
That's correct. I've done something similar to Minisign. Handling that sort of problem is way beyond what one person can manage anyway. I'm only a student and not even a computer science student. The recommended way of sharin
16.
▲
by
samuel-lucas6
5y ago
You can currently do the following with Kryptor: $ kryptor -e test.jpg The difference is that this uses your encryption private key. However, I will look into just supporting -p because that's a fair point, although that would be trick
17.
▲
Show HN: Kryptor – A simple, modern, and secure encryption tool
(kryptor.co.uk)
78 points
by
samuel-lucas6
5y ago
|
40 comments