Incidentally, using standard crypto (say, TLS) is not an excuse to skip writing a spec. It just means you have a short spec. Which is good!
@matthew_d_green I'm writing a spec. How do I know I'm writing a *good* spec?
-
-
@bascule Does it 1. Explain the system 2. Give a threat model 3. Precisely document the crypto? And not 4. otherwise suck? Then you're ok. -
@matthew_d_green 1) check 2) check 3) I think so? 4) not sure: https://github.com/cryptosphere/cryptosphere/wiki/Data-Model … -
@bascule Blake2bXSalsa20Poly1305? -
@matthew_d_green is that a bad name for that particular construction? -
@bascule Haha, no. It just made me laugh. -
@matthew_d_green I should probably change it :| -
@bascule No, it's fine. Now that I get you're doing convergent encryption it makes sense.
End of conversation
New conversation -
-
-
@bascule nb: not a cryptographer, just an armchair protocol-implementor :)Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.