Re: [dev] securiy guidance

2018-03-08 Thread Michael Forney
On 2018-03-07, pet...@riseup.net wrote: > Looking at the chacha API one needs to use a nonce, in the monocypher > implementation it is 24 bits wide, which would give the option of almost > 17M runs with a single key. IIUC adding a salt would further randomize > the output and possibly prevent some

Re: [dev] securiy guidance

2018-03-08 Thread Michael Forney
On 2018-03-07, pet...@riseup.net wrote: > On 2018-03-07 00:23, Michael Forney wrote: >> Another related project I've been following is https://monocypher.org/ >> >> It has a quite permissive license and encourages inlining the source >> like you want. > > Hi Michael, > > thanks, this looks really