Intuition for Cryptography
azeemba.com
azeemba.com
I like Peter Gutmann's work. I always thought he coded well. Libsodium also looks good. I know the authors behind ssleay, which became OpenSSL and they were people of good intent but the sheer number of exposed interfaces in that library.. its way way out of control.
The key difference is that anyone who can verify a MAC could also have created it, whereas with a signature only one entity could create the signature but anyone at all can verify it (the public key is public).
MACs therefore allow repudiation of the authenticated data (one party can claim that any other party with the shared key created the MAC), while signatures prevent that (only the holder of the private key could have signed).
They're related, in that they both provide message authentication and integrity, but otherwise quite different constructions.
[0] https://crypto.stackexchange.com/questions/14487/can-someone...
I'd be curious how it reads to a layman.
I find a lot of the PGP hate to be a little overblown, but anyone who's engaged honestly with the issues ought to be able to admit that PGP just isn't a very good tool, and age quite nicely provides an alternative to the last remaining reasons a person could have to still cling to PGP today.
The first time `age` is mentioned is halfway down in the article. `age` is only mentioned twice and both times as a reference to cite their usage of specific algorithms. I thought it would be more appropriate to cite algorithm choices of modern software written by security experts than me picking algorithms.
I also don't describe what `age` is and its use-cases. So I would have trouble calling that marketing.