paseto-spec
Halite
paseto-spec | Halite | |
---|---|---|
4 | 7 | |
146 | 1,111 | |
6.8% | 0.0% | |
0.0 | 0.0 | |
5 months ago | almost 2 years ago | |
PHP | ||
- | Mozilla Public License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
paseto-spec
-
Age and Authenticated Encryption
Another signcryption scheme as described in the article is also implemented by the libsodium author as an extension:
https://github.com/jedisct1/libsodium-signcryption
It's unclear from the article if this is the same algorithm age uses.
Signcryption schemes are also a good candidate algorithm for replacing JWTs and PASETO as they suffer from no algorithm confusion, and don't need what PASETO calls "Algorithm Lucidity" and serve both plaintext authentication, authenticated encryption, sender receiver verification, and shared key generation that can be used for unlimited encrypted streaming, for example with libsodium's crypto_secretstream API.
https://doc.libsodium.org/secret-key_cryptography/secretstre...
https://github.com/paseto-standard/paseto-spec/blob/master/d...
- Paseto is everything you love about JWT without any of the design deficits
-
PASETO Reference Implementation Release Notes (new protocol versions)
The rationale for V3/V4 may be of particular interest for this forum.
-
PASETO v2.0.0 released! (Lengthy release notes)
Whether you're curious or skeptical, we believe in transparency, so the detailed rationale for these exact changes in V3/V4 is available here.
Halite
- sodium_crypto_secretbox
-
Does Halite do PGP?
I'm trying to find a PHP package that will handle PGP encryption/decryption. Halite keeps coming up but I can't tell from searching if it handles PGP. If it doesn't, can you recommend a PHP package that does? Thanks!
-
Sodium encryption and digital signing made simple
Sounds like https://github.com/paragonie/halite. What does this do better?
- Halite (usable cryptography library for PHP) version 5.0.0 released (Security Improvements within!)
-
Weekly "ask anything" thread
One of the Golden Rules of Computing is "Never roll your own Crypto" (without a PhD in Cryptography). If you need to encrypt something at rest I'd recommend the really very excellent Halite Library.
-
PASETO v2.0.0 released! (Lengthy release notes)
10,000%. I love Halite.
-
PHP.Net Documentation for ext/sodium Coming Soon
Excellent job! I've been using the https://github.com/paragonie/halite library on top of Sodium just so I don't have to re-work everything out, but this is going to be nice for cases when including third party libraries isn't possible!
What are some alternatives?
php-jwt - PHP package for JWT
PHP Encryption - Simple Encryption in PHP.
spec - Spec and acceptance tests for the Fernet format.
PHPSecLib - PHP Secure Communications Library
branca - :key: Secure alternative to JWT. Authenticated Encrypted API Tokens for Go.
HTML Purifier - Standards compliant HTML filter written in PHP
paseto - Platform-Agnostic Security Tokens
PHP IDS - PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application
libsodium-signcryption - Signcryption using libsodium.
PHP SSH - An experimental object oriented SSH api in PHP
random_compat - PHP 5.x support for random_bytes() and random_int()
IniScan - A php.ini scanner for best security practices