MongooseWhere programmers kick back and build silly things together.

All help topics · Link to this topic

Showing help on '$encryption_utils'

General information on $encryption_utils:
----
Symmetric encryption utilities for secure messaging.

Encryption uses HMAC-SHA256 in counter mode (CTR) for keystream generation, with encrypt-then-MAC authentication to detect tampering. Each message gets a random nonce, so encrypting the same plaintext twice produces different ciphertext.

Core verbs:
:encrypt(value, key) - encrypts strings, lists, or maps
:decrypt(ciphertext, key) - reverses encryption
:generate_key() - creates a random 256-bit key (hex)
:derive_key(passphrase, player1, player2) - derives key from shared secret

Keys are 64-character hex strings. Parties must have the identical key to encode/decode.

Note: This is symmetric encryption. Server administrators with database access can read stored keys. For stronger security, keys should be stored in an encrypted vault or kept client-side.