[Cryptography] At what point should people not use TLS?

Peter Gutmann pgut001 at cs.auckland.ac.nz
Fri Apr 8 02:35:54 EDT 2016


Brian Gladman <brg at gladman.plus.com> writes:

>On 07/04/2016 17:16, Bill Cox wrote:
>> Noise Pipes looks very cool, but I cannot find any source code used by
>> WhatsApp that implements Noise Pipes.  Can any of you folks find it?  I
>> am interested in trying to understand the security of their
>> implementation, but can't find the source code.
>
>I also looked for it as I wanted to find out well it was implemented. But
>like yourself, I could not find anything.

All I found was a very informal discussion of it:

https://github.com/noiseprotocol/noise_spec/blob/master/noise.md

Trevor Perrin is someone who knows what he's doing, but still, that's an
incredibly informal description to have to evaluate the design by.  It's also
just another STS-style design, they're not hard to invent but pretty hard to
get all the details right, which the informal nature of the spec doesn't help
with.

Peter.


More information about the cryptography mailing list