Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reading about djbs primitive making its way in to TLS, and all the hacks being made to TLS, reminded me of CurveCP[0] and makes me wonder whether its an idea worth revisiting.

For those interested in playing with Salsa20 & poly1305 authenticated encryption outside of TLS there's Sodium[1] which has trivial C and C++ APIs and is based on djbs Nacl[2]

I'd also refer people to Matt Greens post 'How to chose an Authenticated Encryption mode'[3]. There are some interesting alternatives out there like OCB (0.7 - 0.8 cycles/byte, free for FOSS despite patents, and more understandable for mortals).

[0] http://curvecp.org/

[1] https://github.com/jedisct1/libsodium

[2] http://nacl.cace-project.eu/box.html

[3] http://blog.cryptographyengineering.com/2012/05/how-to-choos...



CodesInChaos has documented some problems with the CurveCP key exchange:

http://codesinchaos.wordpress.com/2012/09/09/curvecp-1/


Yep, this was pointed out to me not so long ago here on HN. Still, ZeroMQ for example has picked it up (adapted) for CurveZMQ.

[Edit] Oh, I see Peter Hintjens commented on that post re: that.


I asked Phil Rogaway in person about OCB mode and he said it's free and usable for all nonmilitary uses, even for businesses. For more info about the specific license you can email him personally, he's a really nice and helpful dude.


You can also read the license for OCB to confirm this:

http://www.cs.ucdavis.edu/~rogaway/ocb/license.htm

OCB is neat; unfortunately, the patent means it's also become exotic. Lesser authenticated encryption have also become absurdly fast. Also: I dispute the idea that OCB is easier to understand than GCM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: