djb's cryptography is great, but djb's implementations leave something to be desired.
djb's cryptography is great, but djb's implementations leave something to be desired.
So, I don't see the problem here. If these guys had tried to cobble together a replacement for NaCl out of pieces like the curve25519-donna code, that would be a problem, because there's more potential to screw that up.
I don't like the fact that TinySSH modified TweetNaCl, and added back MD5:
/*
Based on tweetnacl 20140427 (http://tweetnacl.cr.yp.to software.html)
- updated int/uint types to crypto_int/crypto_uint
- added crypto_stream_chacha20
- added crypto_hash_sha256
- added crypto_hash_md5
*/
I mean they use TweetNaCl because it has "state-of-the-art crypto", but then they add back MD5. Something is wrong here ... no older cryptographic primitives - rsa, dsa, classic diffie-hellman, md5, sha1, 3des, arcfour, ...
It is actually used in the code though. I didn't look into for what it was used though.The fingerprint is 47 characters when printed, the key itself is 64. Since the key is so short does the fingerprint still server a useful purpose, or would it be enough to print only the key?
There's a reason why libsodium's tag line is "P(ortable|ackageable) NaCl-based crypto library".
The word of distros/packagers isn't gospel, but it counts for a lot, considering that (for better or worse) most people won't even think about using something not available as a package.