Reading about djbs primitive making its way in to TLS, and all the hacks being made to TLS, reminded me of CurveCP[0] and makes me wonder whether its an idea worth revisiting.
For those interested in playing with Salsa20 & poly1305 authenticated encryption outside of TLS there's Sodium[1] which has trivial C and C++ APIs and is based on djbs Nacl[2]
I'd also refer people to Matt Greens post 'How to chose an Authenticated Encryption mode'[3]. There are some interesting alternatives out there like OCB (0.7 - 0.8 cycles/byte, free for FOSS despite patents, and more understandable for mortals).
I asked Phil Rogaway in person about OCB mode and he said it's free and usable for all nonmilitary uses, even for businesses. For more info about the specific license you can email him personally, he's a really nice and helpful dude.
OCB is neat; unfortunately, the patent means it's also become exotic. Lesser authenticated encryption have also become absurdly fast. Also: I dispute the idea that OCB is easier to understand than GCM.
For those interested in playing with Salsa20 & poly1305 authenticated encryption outside of TLS there's Sodium[1] which has trivial C and C++ APIs and is based on djbs Nacl[2]
I'd also refer people to Matt Greens post 'How to chose an Authenticated Encryption mode'[3]. There are some interesting alternatives out there like OCB (0.7 - 0.8 cycles/byte, free for FOSS despite patents, and more understandable for mortals).
[0] http://curvecp.org/
[1] https://github.com/jedisct1/libsodium
[2] http://nacl.cace-project.eu/box.html
[3] http://blog.cryptographyengineering.com/2012/05/how-to-choos...