from Daniel J. Bernstein, replying to "Matthew Green (@matthew_d_green)":

libpqcrypto ( includes a simple command-line interface designed to prevent common security failures: everything aims for CCA2, verification failures produce empty output in case errors are ignored, etc. But still needs consttime + tons of security review.


from "Orthanc (@Orthanc)", replying to "Matthew Green (@matthew_d_green)":

Does openssl count?

from "Matthew Green (@matthew_d_green)", replying to "Orthanc (@Orthanc)":

The process of public key encrypting a file is pretty janky.

from "truelai (@truelai)", replying to "Matthew Green (@matthew_d_green)":

Is "janky" a technical criticism?

from "Matthew Green (@matthew_d_green)", replying to "truelai (@truelai)":

It’s a corollary of “sucky”. But seriously, OpenSSL public key encryption is bad.