Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Despite having been the main maintainer of Weave Net for ~4 years, I have no idea what you are talking about. Weave Net used Google's NaCL library from day 1; later adding optional AES using the in-kernel implementation.

https://github.com/weaveworks/weave/blob/master/site/concept...



The key exchange was/is totally custom without using anything standard, though it uses standard concepts (DH, though it does some non-standard things with it), which *might* be secure, but as far as I know, never actually put to the test.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: