Gentoo Archives: gentoo-dev

From: "Marty E. Plummer" <hanetzer@×××××××××.com>
To: gentoo-dev@l.g.o
Subject: Re: mcrypt status (Re: [gentoo-dev] Idea for a new project: gentoo-libs)
Date: Sat, 04 Aug 2018 18:07:45
Message-Id: 20180804180554.vdzinpcbqsh7s2ol@proprietary-killer
In Reply to: mcrypt status (Re: [gentoo-dev] Idea for a new project: gentoo-libs) by Andrew Savchenko
1 On Sat, Aug 04, 2018 at 11:43:28AM +0300, Andrew Savchenko wrote:
2 > On Mon, 25 Jun 2018 07:59:47 +0200 Hanno Böck wrote:
3 > > On Fri, 22 Jun 2018 21:50:50 -0500
4 > > "Marty E. Plummer" <hanetzer@×××××××××.com> wrote:
5 > >
6 > > > So, as you may be aware I've been doing some work on moving bzip2 to
7 > > > an autotools based build. Recently I've ran into app-crypt/mhash,
8 > > > which is in a semi-abandoned state (talking with the maintainer on
9 > > > twitter atm), and I was thinking it may be a good idea to set up a
10 > > > project for keeping these semi-abandoned and really-abandoned
11 > > > libraries and projects up to date and such.
12 > >
13 > > This is a common problem, however if you want to make this reasonable
14 > > you wouldn't make it a gentoo thing, but a cross-distro effort. The
15 > > idea has been tossed around a lot, but noone yet started implementing
16 > > it.
17 > >
18 > > However keeping things alive may not always be the right option.
19 > > There's a reason mcrypt is abandoned. It's an ancient crypto library,
20 > > crypto is moving forward, there are better options.
21 >
22 > Do you have any evidence that mcrypt should not be used?
23 >
24 > Symmetric cryptography is quite conservative and it took years and
25 > even decades for algorithms and their implementations to become
26 > trusted, so there is nothing wrong in using good old verified
27 > software.
28 >
29 > Actually for local symmetric encryption this is the best tool I
30 > know.
31 >
32 > Best regards,
33 > Andrew Savchenko
34 It seems that every last person commenting on this is talking mcrypt,
35 not mhash, which is what I mentioned in the first place. As far as I can
36 tell, these are entirely differnt projects which just happen to have a
37 similar name.

Replies

Subject Author
Re: mcrypt status (Re: [gentoo-dev] Idea for a new project: gentoo-libs) Andrew Savchenko <bircoph@g.o>