> Well, we've already established that the code was wrong...
Hah, it's been a while since I read:
http://www.daemonology.net/blog/2011-01-18-tarsnap-critical-...
Makes me feel a little less bad for the Debian issue with (way!) too low entropy in key-generation.
Refactoring code using crypto dangerous :-/
Have you considered creating a 2.0 on top of NaCL? I could see that it would probably not be a good idea to actually throw out all the existing tarsnap-code etc -- I generally just mean if you'd want to move to a simple, yet "batteries-included"/shrink-wrapped crypto library?