Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So it seems that the Cryptographic Right Answers is lacking a section on "stateless tokens carrying a small payload". What should one do in this case?


I mean, part of the answer is "don't do that" but if you have to, secretbox or PASETO. Part of the problem is that "stateless token" can mean a lot of things depending on context; for internal use you generally want symmetric MAC possibly w/ symmetric encryption, for external use you probably want signing -- all of which have answers in Cryptographic Right Answers :)


I was wondering more about how to format a payload that may be shared between agents in a standard, secure format, but that is probably not even a Cryptographic Question :)


Still the same answer unfortunately: depends on the use case. Sometimes you just want signing, sometimes it's OK to share a key, sometimes...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: