What's the issue?
Section 4.9.4 (Testing for Weak Encryption) includes a few notes about digital signatures.
I'm curious if the section is meant to include signature information, since to me (a novice) encryption and signatures are two different but related aspects of cryptography.
How I noticed this is the Basic Security Checklist has a recommendation for "asymmetric encryption" methods and separately (subsequent bullet), a note about using RSA for signatures.
I can't tell if the first bullet is only about encryption, or if would apply to signatures as well.
How do we solve it?
If the section is in fact only talking about encryption and not signatures, would it be wise to add a section about signatures?
Otherwise, if it meant to cover both, maybe some clarity/additions around acceptable signature algorithms would be good.
Would you like to be assigned to this issue?
What's the issue?
Section 4.9.4 (Testing for Weak Encryption) includes a few notes about digital signatures.
I'm curious if the section is meant to include signature information, since to me (a novice) encryption and signatures are two different but related aspects of cryptography.
How I noticed this is the Basic Security Checklist has a recommendation for "asymmetric encryption" methods and separately (subsequent bullet), a note about using RSA for signatures.
I can't tell if the first bullet is only about encryption, or if would apply to signatures as well.
How do we solve it?
If the section is in fact only talking about encryption and not signatures, would it be wise to add a section about signatures?
Otherwise, if it meant to cover both, maybe some clarity/additions around acceptable signature algorithms would be good.
Would you like to be assigned to this issue?
With some guidance as to what the intent of that section is, I could do a PR.