I would.
The idea might not be bad, but the implementation is.
They use a pure software AES implementation that, due to its reliance on S-boxes, opens the door for cache-timing attacks.
Offending file: https://github.com/keybase/triplesec/blob/master/src/aes.ice...
Permalink: https://github.com/keybase/triplesec/blob/bb0b2f449cc28ca402...
Issue: https://github.com/keybase/triplesec/issues/47 (opened March 17, still collecting dust)
Reference: http://cr.yp.to/antiforgery/cachetiming-20050414.pdf
AES-NI or bust.
> The FAQ says something about plans for a future streaming API. Please do not do this, at least for the decrypt operation. Streaming decryption APIs expose application developers to not-yet-authenticated plaintext.
I've written a streaming PoC to encrypt/decrypt file handles in PHP. During the decryption process, it first recalculates the HMAC over the entire file then verifies it with the one stored before decrypting. (Yes, in constant time too.) It's slower than just blindly decrypting, but more trustworthy.
Not quite the same as streaming network resources, but I figured that bit of nuance is worth mentioning.
The experiment lives here if you're interested in schooling me on some matter I overlooked, though I'm going to significantly rewrite it before I propose it to the project I was PoCing it for:
https://github.com/paragonie-scott/php-crypto-stream
(For starters, the actual pull request won't be using CBC.)