Skip to content

Cryptography - encryption vs signatures #734

Description

@JCapriotti

What's the issue?
Section 4.9.4 (Testing for Weak Encryption) includes a few notes about digital signatures.

I'm curious if the section is meant to include signature information, since to me (a novice) encryption and signatures are two different but related aspects of cryptography.

How I noticed this is the Basic Security Checklist has a recommendation for "asymmetric encryption" methods and separately (subsequent bullet), a note about using RSA for signatures.

I can't tell if the first bullet is only about encryption, or if would apply to signatures as well.

How do we solve it?
If the section is in fact only talking about encryption and not signatures, would it be wise to add a section about signatures?

Otherwise, if it meant to cover both, maybe some clarity/additions around acceptable signature algorithms would be good.

Would you like to be assigned to this issue?

  • Assign me, please!
    With some guidance as to what the intent of that section is, I could do a PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

reviseNeeds quality review, updates, or revision

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions