Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think people got turned off from them when it came to light they had invented their own cryptography without doing any vetting that it was actually secure. At least, that’s why we moved away from it as quickly as possible with our reasoning being: “if someone is foolish enough to roll their own crypto, what else are they doing foolishly?”


Despite having been the main maintainer of Weave Net for ~4 years, I have no idea what you are talking about. Weave Net used Google's NaCL library from day 1; later adding optional AES using the in-kernel implementation.

https://github.com/weaveworks/weave/blob/master/site/concept...


The key exchange was/is totally custom without using anything standard, though it uses standard concepts (DH, though it does some non-standard things with it), which *might* be secure, but as far as I know, never actually put to the test.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: