[RFC][PATCH][BZ 2100] blowfish support in libcrypt
Dmitry V. Levin
ldv@altlinux.org
Tue Jun 20 11:51:00 GMT 2017
On Tue, Jun 20, 2017 at 01:26:02PM +0200, Thorsten Kukuk wrote:
> On Thu, Jun 01, Florian Weimer wrote:
>
> > The other question is why we should add Blowfish support when the cipher
> > is pretty much on everyone's banned list.
>
> We should not add it. The whole interface is poorly designed and complicated
> to use.
For more than 16 years that this interface (crypt_rn, crypt_ra, and
crypt_gensalt*) is in use, it's called poorly designed and complicated
to use for the first time AFAIK. Thorsten, could you elaborate, please?
> And there are today better cipher. Blowfish is outdated today.
Well, bcrypt is not blowfish. :)
--
ldv
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20170620/5a59b961/attachment.sig>
More information about the Libc-alpha
mailing list