Closed GoogleCodeExporter closed 9 years ago
I think this all seem ok. I am by no means a cryptographer, but the code itself
seems
safe and correct.
Original comment by chrisisbeef
on 17 Dec 2009 at 7:34
The method, computeDerivedKey(), is now from lines 78-188 as of 2010-02-13
(ESAPI-2.0-rc5).
Original comment by kevin.w.wall@gmail.com
on 13 Feb 2010 at 5:06
NSA has volunteered their services to review at least the ESAPI crypto code.
Thanks!
Original comment by kevin.w.wall@gmail.com
on 31 Jul 2010 at 2:21
Waiting on the NSA
Original comment by manico.james@gmail.com
on 1 Nov 2010 at 12:49
Original comment by chrisisbeef
on 20 Nov 2010 at 9:55
Addressed via feedback from NSA (Jessica Fitzgerald-McKay and Andy Sampson) and
Jeffrey Walton.
Recommended changes implemented in SVN revisions 1682, 1683, 1699, 1700, 1705,
1706,
1707, 1711, and 1712. See SVN commit comments for details.
Note that this was fixed in TRUNK, not in branches.
Original comment by kevin.w.wall@gmail.com
on 4 Feb 2011 at 7:12
Original issue reported on code.google.com by
kevin.w.wall@gmail.com
on 17 Dec 2009 at 4:29