Hall of FameLatacora201811 min readintermediate
Cryptographic Right Answers
Summary
Latacora’s 2018 guide lists the safe, low‑maintenance crypto choices for developers: use modern AEAD (XSalsa20‑Poly1305), 256‑bit keys, SHA‑2, libsodium/Curve25519, and strong password hashes. Avoid legacy algorithms like RSA, AES‑CBC, SHA‑1, and custom constructions.
- Prefer AEAD constructions such as XSalsa20‑Poly1305 from libsodium; avoid AES‑CBC/CTR and manage nonces carefully.
- Use 256‑bit symmetric keys and elliptic‑curve primitives (Curve25519, Ed25519) for asymmetric crypto; discard RSA and older DSA/ECDSA.
- Hash with SHA‑2 (SHA‑256 or SHA‑512/256); avoid SHA‑1, MD5, and other deprecated hashes.
- For password storage, choose scrypt, argon2, or bcrypt; treat PBKDF2 as a fallback and never roll your own scheme.
Any engineer building services that handle secrets should follow these hardened defaults to avoid common cryptographic pitfalls.
6/10



