Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:93799 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 59700 invoked from network); 5 Jun 2016 08:13:07 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 5 Jun 2016 08:13:07 -0000 Authentication-Results: pb1.pair.com smtp.mail=php@fleshgrinder.com; spf=permerror; sender-id=unknown Authentication-Results: pb1.pair.com header.from=php@fleshgrinder.com; sender-id=unknown Received-SPF: error (pb1.pair.com: domain fleshgrinder.com from 77.244.243.85 cause and error) X-PHP-List-Original-Sender: php@fleshgrinder.com X-Host-Fingerprint: 77.244.243.85 mx104.easyname.com Received: from [77.244.243.85] ([77.244.243.85:59964] helo=mx206.easyname.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 84/B0-55579-01FD3575 for ; Sun, 05 Jun 2016 04:13:05 -0400 Received: from cable-81-173-133-15.netcologne.de ([81.173.133.15] helo=[192.168.178.20]) by mx.easyname.com with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1b9TB6-00049j-NM; Sun, 05 Jun 2016 08:13:00 +0000 Reply-To: internals@lists.php.net References: To: Scott Arciszewski , Pierre Joye Cc: Stas Malyshev , PHP internals Message-ID: <8ebf9e48-62e5-fae5-d234-448be3c1f9d2@fleshgrinder.com> Date: Sun, 5 Jun 2016 10:12:49 +0200 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.1.1 MIME-Version: 1.0 In-Reply-To: Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="E707KvilrcPDACMq6XQVnothII945ePR9" X-ACL-Warn: X-DNSBL-BARRACUDACENTRAL Subject: Re: [PHP-DEV] [RFC] Libsodium - Discussion From: php@fleshgrinder.com (Fleshgrinder) --E707KvilrcPDACMq6XQVnothII945ePR9 Content-Type: multipart/mixed; boundary="F9BCsVwgGRsGuNcxbThs3vnjFQElRLQ3V" From: Fleshgrinder Reply-To: internals@lists.php.net To: Scott Arciszewski , Pierre Joye Cc: Stas Malyshev , PHP internals Message-ID: <8ebf9e48-62e5-fae5-d234-448be3c1f9d2@fleshgrinder.com> Subject: Re: [PHP-DEV] [RFC] Libsodium - Discussion References: In-Reply-To: --F9BCsVwgGRsGuNcxbThs3vnjFQElRLQ3V Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable On 6/5/2016 9:46 AM, Scott Arciszewski wrote: > =E2=80=8BLibsodium already =E2=80=8Bknocks it out of the park compared = to OpenSSL and > Mcrypt. If we want to talk about a higher-level abstraction-- such as > what's provided by paragonie/EasyRSA + defuse/php-encryption or > paragonie/halite-- I wholeheartedly endorse that discussion. But I don'= t > think we should try to solve that problem with this particular RFC. >=20 > In closing, I don't disagree that a simple crypto API is a good goal to= > have. I just think the ideal you're discussing is: >=20 > A. Out of scope, and > B. Kind of belittling to how much of an improvement libsodium is to wha= t we > already have. >=20 You are completely ignoring that once this is out the door there is no way back. We already see many problems in the current API and we should address them until we reach a point where the majority does not see major problems anymore. Doing anything else is just irresponsible! --=20 Richard "Fleshgrinder" Fussenegger --F9BCsVwgGRsGuNcxbThs3vnjFQElRLQ3V-- --E707KvilrcPDACMq6XQVnothII945ePR9 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJXU98JAAoJEOKkKcqFPVVrfykQAMygKTLedFNPaw8ygtNsxnGE geJzGV/fWKSmD1nsYyQDNrr5mKRcQnQf9vIc5b2w3VdNzEeuRruFl5JsoRO0gVSO Y5XL6YlqEYBWitbqnQPbVU+s7cMnWj9XafBVsXjfS20rP/7lFEkNxsGvTcgL/XO3 ucOdOtOPYowtJoPGGgaT0lNQY4Kcvbv4LQIbXY2HEMsGb6Wxfytr66SxXbqqMmfq epjbISy8bEz+9f40ZvyU0nMk62pzeW+8Q72dxzhCTRRl3bhLgJffPxZimHKkoZb6 V8eujVrz6F2YX27HtTUvp3zG0tSxK3n+yP0Ma32kEpS6jrO4lel/Mw1RO5B6+NUa dil58zw1M6FIOcdb8MTtSNY+5rnL8aP5Ynou78rxOT6DU2wGL/mv+sKaXmDncGZT nnNIgs1/zdhdpBa8qW2jNrFfKZQNHpAjNxHM7fza+zy/XGojokLKhoPSiNRfyuri VJObT+lOnU9gKRcBDTjsVVjSDbPaceHowj3+ciuWC7aXDu035+3pKQVCtlEsigAc aybxACZaUHL/dOzyZpUqyiiJ/ZIF7VKmisd0VZb6YvwITGRB0DdL0Bmfj+poxJZO jdISOCRAf4pgd+9vxPY4GwSGwx4fIgovAJbHUarJcfvLifRqsOqtIX39+u3Tbdno m15FB9rUqndE8lLcg/EL =mPid -----END PGP SIGNATURE----- --E707KvilrcPDACMq6XQVnothII945ePR9--