Re: ABI guarantees

From: Lexi Winter <ivy_at_freebsd.org>
Date: Mon, 18 Aug 2025 21:01:46 UTC
Vadim Goncharov:
> Don't know about IPsec but deleting blowfish was surely a mistake - it is
> not broken and could be used e.g. in IoT where space constraints matter, for
> those who know what they are doing.

Blowfish (along with 3DES) was broken by Sweet32.  it might still be
secure with certain specific constraints (like regular key rotation)
but i don't think it's wrong to err on the side of not shipping known
broken cyphers.