Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The real problem is the lack of a REAL crypto API which does not suck as an interface for security and with which, <b>using default parameters</b>, you get good security. That is the problem. All the ones I know are too low level.

That is an engineering problem: there are the pieces but there is no real engine.

But this is my biased and humble opinion after using OpenSSL.

I am not advocating a 'just works one way' API. I am asking for a real engineering effort to create a 'dumb people can use this safely as long as they follow the simple instructions'.

If you (developer) need to know why encrypt+mac != mac+encrypt, then the security engineers have not done their job. If you need to know the difference between ECB and CBC, the security engineers have not done their job. If you need to know about the IV in AES, then ... (just repeat).



This is the whole problem Keyczar and Nacl were designed to solve.


Wow, that looks impressive, really (NaCl). However, the online doc is a bit scarce, is it not?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: