Hacker News new | ask | show | jobs
by shanusmagnus 589 days ago
> "Don't rely on a single cipher" is an anti-goal, and a reason your hobby project won't be taken seriously.

Why?

1 comments

If unanticipated issues are discovered, end users may not receive the updates in a timely fashion if, for example, the repo owner is the only committer and they're on vacation when the next Heartbleed 0day hits.

I am confident and trust the OpenSSL and LibreSSL projects each have multiple folks capable of merging and releasing critical updates.

Amazing as he is, Filippo is a single person who presumably has human needs. If he's a Terminator, though, swell, do let me know.

Ah. I was thinking the critique was about combining different crypto methods in serial; I've heard people say this is a bad idea but have never understood why.
Mostly it's just that it doesn't accomplish anything.