Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Documentation #613

Open
jcarver989 opened this issue Sep 24, 2018 · 0 comments
Open

Documentation #613

jcarver989 opened this issue Sep 24, 2018 · 0 comments

Comments

@jcarver989
Copy link

@jcarver989 jcarver989 commented Sep 24, 2018

Hi there,

First off thanks for all the work in building this - crypto is a PITA.

After reading your docs, I had the following questions, which I think would be useful to cover (or clarify) for other people in the docs:

  1. Have any cryptographers reviewed this library? If so who - were they internal or a hired 3rd party - which part(s) did they review? Your docs appear to be asking for a security review, which makes me wonder if this library has been blessed by an actual cryptographer, i.e. Cryptography is hard. Please review and test this code before depending on it for critical functionality.. I do not mean for this to sound accusatory in any way- I'm merely curious as to the current state of this library.

  2. Is this intended to be used in production or is this more of a hobby project/proof-of-concept? I assume you guys use this in production today?

  3. Are there any known (demonstrated) vulnerabilities against anything specific to this library's implementation? Your documentation hints that there might be a known timing attack vulnerability due to it being difficult to check MAC equality in constant time in JS runtimes - what else might exist?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant
You can’t perform that action at this time.