Orderprogramming.devimage danhab99 ( @danhab99@programming.dev ) Programmer Humor@programming.dev • 1 year ago message-square21fedilinkarrow-up1344
arrow-up1344imageOrderprogramming.dev danhab99 ( @danhab99@programming.dev ) Programmer Humor@programming.dev • 1 year ago message-square21fedilink
minus-square koper ( @koper@feddit.nl ) linkfedilink18•1 year agoThe real question is do you encrypt-and-sign or sign-and-encrypt?
minus-square Eufalconimorph ( @Eufalconimorph@discuss.tchncs.de ) linkfedilink20•1 year agoEncrypt then sign. Always authenticate before any other operations like decryption. Don’t violate the cryptographic doom principle.
minus-square tvbusy ( @tvbusy@lemmy.dbzer0.com ) linkfedilinkEnglish18•1 year agoEncrypt then sign. Verification is often much faster than (or at worst as fast as) decryption. Signature can also be verified without decryption key, making it possible to verify the data along the way.
The real question is do you encrypt-and-sign or sign-and-encrypt?
Encrypt then sign. Always authenticate before any other operations like decryption. Don’t violate the cryptographic doom principle.
Encrypt then sign. Verification is often much faster than (or at worst as fast as) decryption. Signature can also be verified without decryption key, making it possible to verify the data along the way.