logoalt Hacker News

emanuele-emtoday at 11:38 AM1 replyview on HN

Per-bucket DEKs with HKDF, hashed policy keys to kill enumeration, HMAC audit chain. This is the kind of boring-correct crypto design I rarely see in Go libraries. memguard for the master key is a nice touch too.


Replies

babaweretoday at 12:01 PM

I was thinking its better to be boring-correct :)

show 1 reply