9 ms·
I was mainly commenting on the design. I actually haven't looked at the implementation. Also, I would put AES side channels somewhat low on the list of practic
by sdevlin 11y ago
I was mainly commenting on the design. I actually haven't looked at the implementation.
Also, I would put AES side channels somewhat low on the list of practical vulnerabilities.
- sarciszewski 11y ago> Also, I would put AES side channels somewhat low on the list of practical vulnerabilities. Sure, but if they're concerned about weaknesses in AES enough to cascade it with other ciphers, ignoring the side-channel inherent to the AES design is pretty silly and indicates a lack of research or foresight. Combine that with no response from their team for threee months after I opened the issue, and I think we can safely conclude that this library is not currently trustworthy. (in b4 "TripleSec Considered Harmful")