Algorithm Agility?
tbray.org
tbray.org
It's a bad idea and people shouldn't build it into new systems. Version the protocol instead, and plan on making it straightforward to upgrade the protocol and lock out old versions.
That being said, for most purposes, you can do worse than using either mutual TLS or Macaroons [0]. As always with cryptography though, the devil is in the details, so for a more thorough discussion, check out @tptacek's "A Child's Garden of Inter-Service Authentication Schemes" [1]. It's one of my favourite treatments of the topic, and discusses the tradeoffs of a few different techniques for different use-cases.
[0] https://en.wikipedia.org/wiki/Macaroons_(computer_science)
It's why I still test my websites with Netscape 3.x and keep http running.
> Be conservative in what you send, be liberal in what you accept.
The first half makes good sense. You should make efforts to ensure your program is producing well-formed output. That's just a statement of software quality.
The second half is dependent on the problem domain. A web browser should do its best to cope with malformed input, sure. An Ada compiler should not, as an important part of its job is to reject erroneous inputs. Similarly, part of the value of XML schemas is to (at least partially) automate the process of detecting invalid data, perhaps so that bad requests can be rejected.
edit Turns out others have spent more time thinking about this than I have: https://en.wikipedia.org/wiki/Robustness_principle#Criticism
I don’t think it’s just a crypto thing, agility is an issue in protocols that need to remain compatible in general.
While on one hand insecure LDAP is convenient for testing, I do think it should really just be removed and require LDAPS.
I would argue given the key lengths of ed25519, not even to do base64, but just do hex encoding.
Sure it is a little longer, but in return you get much simpler encoding and decoding, no worries about flavors of base64 or padding.
In addition, hex encoding is much easier to verbally communicate to someone versus base64.
In a security context, I think making things as simple as possible has big benefits.
Verbal communication is a problem with any system that uses letters. In hex for example; 3, B, C, D and E all sound very much the same.
We have a standard way of dealing with that in the form the NATO phonetic alphabet.
So 3BCDE would be “Tree Bravo Charlie Delta Echo”
Otherwise any completely new system would have to be considered secure, as it would not suffer from any of the issues of any of the older systems. My understanding is that new elliptic curves can have entirely new characteristics not shared by older curves.
So Curve25519 has had 16 years of widespread academic scrutiny. That’s “battle-tested” by modern cryptographic standards.
Maybe you won't change the algorithm, but still want to leave room to add another config parameter. The file format is obvious in a text editor and it's easy to add more stuff.