• reisub@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 days ago

    I think the idea behind opinionated cryptography is not only the idea of “We think this is the best, so you have to use it”, but most importantly it removes all requirements of the protocol supporting cipher negotiation. This makes the protocol much simpler, easier to audit and as a result more secure. And if the cryptography in the protocol ever shows a weakness, then Wireguard v2 needs to be released as a breaking change. See all the SSL/TLS versions

    • r00ty@kbin.life
      link
      fedilink
      arrow-up
      1
      ·
      6 days ago

      Yep. I entirely agree about the good points. I am just always weary about removing options like this, regardless of intention.

      I’d be fine if for example I’m running my own wireguard implementation, I could choose the suite to use, not negotiate anything and ensure my client has the same configuration.

      I’d probably not use it, but I like the option, and knowing that anyone that wants to try to break this now also needs to guess what options I’m running.