Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The SSL/TLS protocol unfortunately uses some known-bad constructions, which lead to intractable issues (see: BEAST, Lucky13 for examples)

NaCl's goals are vastly different to those of SSL/TLS. SSL/TLS aims to provide a simple, clean interface with sane defaults for the majority of simple use-cases, whereas SSL/TLS aims to provide an interface with near-infinite flexibility for the case of providing an encrypted, authenticated tunnel.

NaCl also deliberately does not support lots of ciphers, as that makes it easy for developers to choose poorly, for example, (Alleged) RC4, as is supported in OpenSSL.



Did you mean

> NaCl aims to provide a simple, clean interface ...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: